🛡️ MAL-2026-10151 — buffer-util-internal

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in buffer-util-internal (npm)

Source: amazon-inspector

Package impersonates Feross Aboukhadijeh's widely-used buffer package, copying its author, repository, contributors, and description metadata while publishing under the name buffer-util-internal. The main module index.js contains a top-level IIFE that base64-decodes a hardcoded URL (decoding to https://www.jsonkeeper.com/b/PT0ON), fetches a JSON document from that anonymous paste host, and passes the response's content field directly to eval. The destination URL is hidden behind a variable named tokenStringRe with a misleading // Random string to generate strong random value comment, alongside a second base64 string referencing a sibling paste id. Because the fetched content is attacker-mutable, every consumer that requires this package executes whatever JavaScript the paste host serves at that moment — a full remote code execution primitive on the installer at require time. The package also declares unusual dependencies (axios, execp, request) inconsistent with the legitimate buffer package.

Affected software

MAL-2026-10151 is recorded against 1 package.

  • buffer-util-internal

Timeline and source

Published on 10 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.npmjs.com (Package)
www.npmjs.com (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-10
Updated 2026-08-12
Modified 2026-07-10
Fix URL N/A

Affected Packages

Software From version Fixed in
buffer-util-internal

Free Vulnerability Check

Is your site affected by MAL-2026-10151?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-10151 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.