{"id":"MAL-2026-10586","summary":"Malicious code in crypto-validate-lib (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f3d8b69cab723043b20a628a6cd17f0e5cc64051004d9beb43d4b9ed58dbd9a0)\nindex.js contains a self-invoking IIFE that, 37 seconds after the module is required, reads a base64 blob from test/fixtures/keypairs.dat (a ~53KB opaque file masquerading as test data), decodes it to ~40KB of JavaScript, writes the result to ~/.cache-db/.node-sync/syncd.js with mode 0o700, and spawns it via a detached node child process. Persistence is installed alongside the drop: on Linux a crontab entry is appended running the dropped script every 12 hours, and on Windows a scheduled task named 'WinNodeSync' is created to run it hourly (mod 12). The hidden dot-directory name and the scheduled-task name masquerade as benign Node caching. The package is advertised as a crypto address validator; decoding a bundled opaque blob, writing it to a hidden home-directory path, installing cron/schtasks persistence, and background-executing it has no relationship to that purpose.\n","modified":"2026-08-19T04:30:10.991555174Z","published":"2026-07-14T13:58:43Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-010511","import_time":"2026-07-14T14:37:52.102330701Z","modified_time":"2026-07-14T13:58:43Z","sha256":"f3d8b69cab723043b20a628a6cd17f0e5cc64051004d9beb43d4b9ed58dbd9a0","source":"amazon-inspector"},{"versions":["1.0.2"],"id":"IN-MAL-2026-010534","import_time":"2026-07-14T18:28:26.820988074Z","modified_time":"2026-07-14T17:54:32Z","sha256":"3a4fed71b7064a35b0947a69b3956ad0458fc1440bbd5af37b1eb5c8fc27b64a","source":"amazon-inspector"},{"id":"IN-MAL-2026-010536","import_time":"2026-07-14T18:28:27.124170145Z","modified_time":"2026-07-14T17:54:47Z","sha256":"579c4a08980a1a5f07457ba926ae3f15350adc6ed5ba6dc4bc8c5f3388766d22","source":"amazon-inspector","versions":["1.0.3"]},{"versions":["1.0.0"],"id":"IN-MAL-2026-018349","import_time":"2026-08-19T04:18:13.818458305Z","modified_time":"2026-08-19T04:02:08Z","sha256":"ac365c1e0351e0ae05d6a06baee01d3d65f1c325ea0cda8af2a950546ccf0ccc","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/crypto-validate-lib/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/crypto-validate-lib/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/crypto-validate-lib/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/crypto-validate-lib/v/1.0.0"}],"affected":[{"package":{"name":"crypto-validate-lib","ecosystem":"npm","purl":"pkg:npm/crypto-validate-lib"},"versions":["1.0.1","1.0.2","1.0.3","1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"2f4051def22d5d1d6347a127ecaefc2bb776c926","sha512_sri":"sha512-cZYNXJALTlkfaYlI5Cdagj3JOZoVNzvHIFdPS/iDZrLIUiUnI0E0l/uTs0Sus3oMJnnQLcKE+ygLBmlPr0ozPg=="},"filename":"crypto-validate-lib-1.0.1.tgz"}],"evidence_files":[{"tlsh":"42514245e5f6b2820e71f4b89e7b29337de805e29018da7879ddd0e08f850349479bed","path":"index.js","sha256":"9571dff0efc7bc24e335a031e90250e1816f70de5f7e3d10ca02057afad6f7d8"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/crypto-validate-lib/MAL-2026-10586.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}