{"id":"MAL-2026-10453","summary":"Malicious code in router-processor (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d15d816c739a85908172d716580a6e4cb0655fe7b2fe35293b218db80f9b2625)\nrouter-processor@1.5.2 exposes a getPlugin function that assembles the URL https://svganchordev.net/icons/107 from split constants (protocol, separator, domain, path), fetches a JSON response, and passes the `credits` field to `new Function(...)` which is then invoked with a context object exposing `require`, `process`, `Buffer`, and other Node.js internals. This executes arbitrary attacker-controlled JavaScript with full Node privileges in the caller's process. The package declares dependencies on DPAPI bindings (Windows credential decryption), better-sqlite3, and node-machine-id, which are consistent with an infostealer loader capable of decrypting browser credential stores. The package's identity is inconsistent: package.json describes a router processor while the README advertises a Polymarket SDK, and neither matches the observed behavior of fetching remote code from an SVG-themed cover-story domain. The URL split-construction and the misleading `credits`/`getPlugin` naming are deliberate evasion of casual review.\n","modified":"2026-07-13T15:49:13.573329223Z","published":"2026-07-13T14:22:59Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.5.2"],"id":"IN-MAL-2026-010263","import_time":"2026-07-13T15:30:31.61096972Z","modified_time":"2026-07-13T14:22:59Z","sha256":"d15d816c739a85908172d716580a6e4cb0655fe7b2fe35293b218db80f9b2625"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/router-processor/v/1.5.2"}],"affected":[{"package":{"name":"router-processor","ecosystem":"npm","purl":"pkg:npm/router-processor"},"versions":["1.5.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/router-processor/MAL-2026-10453.json","indicators":{"evidence_files":[{"path":"index.js","sha256":"f03baeca30cfcbb5903b1d93435435be75b45695cae2510970d803a09ba7071d","tlsh":"3ac1616546fa31a36a67e4edf30f10027165e3133759e971f48e42902fca568e5f24e8"}],"package_integrity":[{"filename":"router-processor-1.5.2.tgz","hashes":{"sha1":"f92fcbadf1ca6adc9ec80ef6a7ab3f70029798f8","sha512_sri":"sha512-YadgQj3hsLz1q08sIeybSGkLPtHkhpwjWOol5obIhAPxVjcu3zw3dDN+uNJp6EU6VTMIYeE0dRNrOQ8supiRGQ=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}