OpenSSF/OSV advisory MAL-2026-13736 confirms this npm version as malicious. The package declares native/solver.c as the source of a small C minimax solver and advertises vendor/solver-<platform>-<arch> as its compiled output. The darwin-arm64 slot contains a ~34KB Mach-O consistent with that C source, but vendor/solver-darwin-x64 and vendor/solver-linux-x64 are identical 33,648,788-byte Linux ELF Go binaries (same sha256 05b69666...4420) that link net/http, os/exec, crypto/chacha8, and...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in @nzeros/codebreak (npm)
Details
The package declares native/solver.c as the source of a small C minimax solver and advertises vendor/solver-<platform>-<arch> as its compiled output. The darwin-arm64 slot contains a ~34KB Mach-O consistent with that C source, but vendor/solver-darwin-x64 and vendor/solver-linux-x64 are identical 33,648,788-byte Linux ELF Go binaries (same sha256 05b69666...4420) that link net/http, os/exec, crypto/chacha8, and reference /proc/self/. The postinstall script invokes spawnSync(BINARY, ['selftest']) on install, so on Linux x64 hosts the shipped opaque Go binary runs automatically at install time. The binary's linked packages (network client, process execution, symmetric crypto) and ~1000x size inflation over any plausible build of the declared C algorithm are inconsistent with the documented purpose, and the darwin-x64 slot being populated with a Linux ELF further indicates the vendor tree was not built from the shipped C source. The install-time execution path against unverified, purpose-mismatched bytes on Linux x64 is a fetch-and-execute equivalent embedded in the tarball rather than downloaded, and the destination of any network activity performed by the Go binary cannot be determined from strings alone.
Decision reason
OpenSSF Malicious Packages via OSV confirms @nzeros/codebreak@1.3.0 as malicious (MAL-2026-13736): Malicious code in @nzeros/codebreak (npm)