{"id":"MAL-2026-10418","summary":"Malicious code in note-utilities (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4f093c8536c89f9d6c524ae212051fc45a5244d910afd8ee3abe30698f15b75d)\nThe package masquerades as a pino-style logger (keywords fast/logger/stream/json; lib/ contents copied from pinojs/pino) but ships an additional loader at lib/vcall.js. On require, index.js spawns a detached `node lib/vcall.js` child (detached + unref so it outlives the parent). vcall.js performs an HTTPS GET to https://api.jsonsilo.com/public/94b14d9d-6286-4b13-a7fe-8442e55a31b4, takes the returned `data.model` string, and passes it to `Function.constructor(\"require\", src)` before invoking it with the real `require`. Any JavaScript the third-party JSON hosting endpoint returns runs in the installer's Node process with full module-loading access. The endpoint is attacker-mutable, and the pino-style logger surface is a cover story unrelated to the loader.\n","modified":"2026-07-13T07:47:03.381885006Z","published":"2026-07-13T06:49:02Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-13T07:40:11.582725819Z","modified_time":"2026-07-13T06:49:02Z","sha256":"4f093c8536c89f9d6c524ae212051fc45a5244d910afd8ee3abe30698f15b75d","source":"amazon-inspector","versions":["2.1.2"],"id":"IN-MAL-2026-009829"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/note-utilities/v/2.1.2"}],"affected":[{"package":{"name":"note-utilities","ecosystem":"npm","purl":"pkg:npm/note-utilities"},"versions":["2.1.2"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"lib/vcall.js","sha256":"11c4069edef394345e2c982d398e47837c4f987ec576c1d61ef6e68d39862ec8","tlsh":"64f0a31e31f62168597360f59b4f1112b103d5263a0aeed673cc43410fa946a3bb7bd0"},{"path":"index.js","sha256":"a5746f11a2fd192d52377570a8abcf99976464fb3da13acbb494a13c4ab0ed57","tlsh":"07f0ac4636f5a7a023249ec5fa0ae8372cc2c4317301ecb0d2ceb5e20743a6c86b74d8"},{"path":"package.json","sha256":"d2b75054f373d943497eec64cadb9d37ab1d72a591bd7c4cce5eff42e94d57b1","tlsh":"b3f0ff24cd789e6305ec65924c2a0243a6a19c176918fc2933e7611c4f9d5ff15ff26e"}],"package_integrity":[{"filename":"note-utilities-2.1.2.tgz","hashes":{"sha1":"ac3f5b02d80650092ca3f2f34f884e3e126d2d4d","sha512_sri":"sha512-K0JvWTznXNBEoJjw2KhQRRU4p11QkiPYN04kdQBrHehiOwnv9gsaTZR7j55/8JDN0qpc1zzJkaq/hGlIOGjauA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/note-utilities/MAL-2026-10418.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}