Vulnerability MAL-2026-17418

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 day ago
September 30, 2026 at 12:13 AM UTC
Malicious code in future-scripts (npm)
0.0.2 - 0.0.3
0.0.2 - 0.0.3

Summary

Malicious code in future-scripts (npm)

Details

On October 10, 2026 (local time), boom() calls localStorage.setItem('key', i) 100,000,000 times in a synchronous loop, potentially freezing a browser page. In version 0.0.2, the exported getCommonDateInRanges() calls boom() before input validation; the bundled source map confirms this path. Version 0.0.3 retains boom() as a separate export but no longer calls it from getCommonDateInRanges(), so an explicit call is required. Version 0.0.1 does not contain this routine. This is a static finding; actual victim impact was not observed.

Impacted packages

Timeline

Published
1 day ago
September 30, 2026 at 12:13 AM UTC
Last Modified
3 hours ago
October 01, 2026 at 05:45 AM UTC