Logo
npm

punypump@1.2.5

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-16048

Ecosystem

npm

Summary

The package presents itself as a console shim (index.js is a verbatim copy of console-browserify with description 'Emulate console for all the browsers'), but also ships library.js and test/sessionCtrl.js which auto-execute a stager on module load via initializeService().catch(...). The stager fetches an opaque blob from a base64-hidden URL (config.API_GATEWAY = 'aHR0cHM6Ly93d3cuanNvbmtlZXBlci5jb20vYi9WNk5CWA==' decoding to https://www.jsonkeeper.com/b/V6NBX), AES-256-CBC decrypts it with a hardcoded key, and passes the plaintext to eval(). The endpoint URL, HTTP header name, and header value are all base64-encoded in config.js. Content served from the jsonkeeper.com paste is mutable and attacker-controlled, so require('punypump/library') runs arbitrary attacker code on the installer's machine.

Source: amazon-inspector (6e56cc14096d20f679823bf15af9f44dff039e01f23d2082eba8020200d04a7f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.