{"id":"MAL-2026-10897","summary":"Malicious code in golan125-homepage-test (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (705b0dc2e3b9aafb6d0e72ecb5ad51d873cd59104a045f74bb27161c87a24960)\nPackage self-identifies as a security research test ('Security research test - do not install'). The package.json `homepage` field contains `javascript:alert(document.domain)`, which is an XSS probe targeting any registry or UI frontend that renders homepage values as clickable links without sanitization. The package has no lifecycle scripts (no preinstall/install/postinstall), no network I/O, and `index.js` exports an empty object — installing or requiring this package does not harm the installer's machine. The XSS probe targets registry web UI rendering, not developers who install the package.\n","aliases":["GHSA-6p3c-6jvh-3pg8"],"modified":"2026-09-01T11:31:11.338799899Z","published":"2026-07-20T10:45:09Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-20T13:14:47.144515355Z","modified_time":"2026-07-20T10:45:09Z","sha256":"9de97a7b84132655982784c44670e7d7362fe9b1e7fbb1bd98b156b55014ff6c","source":"reversing-labs","versions":["1.0.0"],"id":"RLMA-2026-05549"},{"id":"IN-MAL-2026-013152","import_time":"2026-08-05T06:00:47.924374897Z","modified_time":"2026-08-05T05:41:21Z","sha256":"705b0dc2e3b9aafb6d0e72ecb5ad51d873cd59104a045f74bb27161c87a24960","source":"amazon-inspector","versions":["1.0.0"]},{"import_time":"2026-09-01T11:18:07.91387416Z","modified_time":"2026-08-24T16:53:41Z","sha256":"42bfb74872fd09d5186219f7dae76465ad6a926d608b7da6702960271630ec94","source":"reversing-labs","id":"RLUA-2026-06262"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/golan125-homepage-test/v/1.0.0"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6p3c-6jvh-3pg8"}],"affected":[{"package":{"name":"golan125-homepage-test","ecosystem":"npm","purl":"pkg:npm/golan125-homepage-test"},"versions":["1.0.0"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"de97aade573a1883af5c1881ee3abef14a7b4532","sha512_sri":"sha512-uB+mRGy8rrSxuyJbqB/KP4i7w4ovFgqlgE4GV6wAiTwyNamDCUQ0hqwm7ZxH0Ca63MiSbWeYFYF7CLcI2TtbKw=="},"filename":"golan125-homepage-test-1.0.0.tgz"}],"evidence_files":[{"tlsh":"c1d0a9689a41903718c5cba43abaa2559b91cc2f2302f908cb9f154884aabf724b560d","path":"package.json","sha256":"fe3c65d1554740acfffb1758462ed08f99377d35fdf72ef5294dabe6674ba92b"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/golan125-homepage-test/MAL-2026-10897.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}