{"id":"MAL-2026-11130","summary":"Malicious code in array-node-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c0dbd4ffa55ee3a0972b3e5e3fef599244049244d9f996a9d8b809a3a3a53e1a)\nThe package's main file index.js is a heavily obfuscated (obfuscator.io RC4+base64 string-array) module whose top-level IIFE runs on require(). It loads https, path, os, fs, child_process, and crypto; assembles a 4-octet host string via repeated.concat calls to hide the destination; issues an https GET; pipes the response through crypto.createDecipheriv (AES) with a sha256-derived key; writes the decrypted bytes to a file under os.tmpdir(); and executes that file via child_process with windowsHide and cwd set to the user's home directory. The package's declared purpose ('array-node-utils') has no relationship to the shipped code — the module contains no array-handling logic, only the fetch-decrypt-exec chain.\n","modified":"2026-07-28T14:37:23.024962549Z","published":"2026-07-28T13:38:38Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-010934","import_time":"2026-07-28T14:19:59.909107928Z","modified_time":"2026-07-28T13:38:38Z","sha256":"c0dbd4ffa55ee3a0972b3e5e3fef599244049244d9f996a9d8b809a3a3a53e1a","source":"amazon-inspector","versions":["1.0.9"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/array-node-utils/v/1.0.9"}],"affected":[{"package":{"name":"array-node-utils","ecosystem":"npm","purl":"pkg:npm/array-node-utils"},"versions":["1.0.9"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"3a96c07468a2adea3fab5cdfdee801fdb557382a128b0e62b34f013400e5266d","tlsh":"ceb2868d3fd2f0a04237b0f76a1b6895e13aac9cb2cc9409f7a5f058fd58354d165b68","path":"index.js"}],"package_integrity":[{"filename":"array-node-utils-1.0.9.tgz","hashes":{"sha1":"3cddce7b3696de276984d15af3ee4a04411beb55","sha512_sri":"sha512-MJ+LPfgCxLWINtm247TrBYK4OHg3rgbRgJrt1amYQsOR7CMzeGjMpLo3VhIhJtBTiK4TkJIP9XUXlGhbPoZxGg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/array-node-utils/MAL-2026-11130.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}