🛡️ MAL-2026-10151 — buffer-util-internal
Description
Malicious code in buffer-util-internal (npm)
Source: amazon-inspector
Package impersonates Feross Aboukhadijeh's widely-used buffer package, copying its author, repository, contributors, and description metadata while publishing under the name buffer-util-internal. The main module index.js contains a top-level IIFE that base64-decodes a hardcoded URL (decoding to https://www.jsonkeeper.com/b/PT0ON), fetches a JSON document from that anonymous paste host, and passes the response's content field directly to eval. The destination URL is hidden behind a variable named tokenStringRe with a misleading // Random string to generate strong random value comment, alongside a second base64 string referencing a sibling paste id. Because the fetched content is attacker-mutable, every consumer that requires this package executes whatever JavaScript the paste host serves at that moment — a full remote code execution primitive on the installer at require time. The package also declares unusual dependencies (axios, execp, request) inconsistent with the legitimate buffer package.
Affected software
MAL-2026-10151 is recorded against 1 package.
- buffer-util-internal
Timeline and source
Published on 10 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| buffer-util-internal | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-10151?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-10151 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.