MAL-2026-13631
Dashboard / Malicious Package / MAL-2026-13631
MAL-2026-13631
Summary: Malicious code in localization-fixer (npm)
Details: Source: amazon-inspector (72446c1307e81047c64d819d3485fa77062061c8c9d4d0b38b42e311137c8701) On require of the package's main entry, a top-level `if (isServer) syncLanguageSystem()` fetches a JSON payload from https://api.jsonbin.io/v3/b/6a764665da38895dfec7cd5d and executes the returned `record.value` field as JavaScript, both by writing it to a temp file and running it via `child_process.fork` and via `new Function('require', payload)(require)` in a separate module-load IIFE that pulls https://api.jsonbin.io/v3/b/6a718a58da38895dfeb6e2ed. Both sinks pass the Node `require` to the constructed function, granting full Node capabilities to whatever the mutable jsonbin.io bin currently serves. Function and variable names (`syncLanguageSystem`, `LANG_SOURCE`, `lang_pass_key`) frame the fetch-and-exec as a localization-sync feature, but the advertised purpose of the package has no need to evaluate remote bytes. The jsonbin.io bins are attacker-mutable, so the payload delivered to any installer is arbitrary and can change at any moment.
References: https://www.npmjs.com/package/localization-fixer/v/1.1.1, https://www.npmjs.com/package/localization-fixer/v/1.0.1
Affected packages
Package
Name: localization-fixer
Purl: pkg:npm/localization-fixer
Affected ranges
Type: N/A
Events:
