{"id":"MAL-2026-11542","summary":"Malicious code in osinthell (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (458757b4c185e84321b45bd7fec158459300d68106826e5774df2399818c7916)\nThe package's only exported function, sorgu(), invokes 26 sibling modules under public/a/b/.../z/ that carry out an immediate, irreversible destructive attack on the caller's Windows host. Observed behaviors include: opening \\\\.\\PhysicalDrive0 and overwriting the MBR with a zeroed 512-byte buffer (h.js); recursive deletion of C:\\ and C:\\Windows\\System32 (c.js, d.js); running `format C: /Q /Y` and `rd /S /Q C:\\` (f.js); taskkill of winlogon/csrss/explorer/dwm (e.js); overwriting C:\\Windows\\System32\\drivers\\etc\\hosts to blackhole google.com, discord.com, github.com, youtube.com, reddit.com, microsoft.com, and windows.com to 0.0.0.0 (g.js); a self-replicating fork bomb spawning cpus*200 detached node processes plus 1000 cmd loops and 500 powershell infinite loops (i.js); repeated 1GB Buffer allocations in an infinite loop (j.js); unbounded intervals for CPU exhaustion (b.js, y.js); download of a JPEG from https://cdn.discordapp.com/attachments/1525228680803123300/1532140349378531328/photo-output.jpg into %TEMP% and forced fullscreen display via start/mshta/powershell WinForms (a.js); and a forced immediate reboot via `shutdown /r /f /t 0` (z.js). The package name and advertised utility purpose are a cover; the exported API is the payload.\n","modified":"2026-08-05T03:20:52.042056959Z","published":"2026-08-04T22:05:16Z","database_specific":{"malicious-packages-origins":[{"sha256":"4323c2f3c854c418907138b8caca1e8a74a801cd1108e2d34b4da4f384728174","source":"amazon-inspector","versions":["1.9.5"],"id":"IN-MAL-2026-011325","import_time":"2026-08-04T22:30:11.012763635Z","modified_time":"2026-08-04T22:05:16Z"},{"id":"IN-MAL-2026-011328","import_time":"2026-08-04T22:30:11.145118279Z","modified_time":"2026-08-04T22:05:42Z","sha256":"4c053414abcdfcca23c4f9d705fe32d7d735389ae13a2d5490da107792b9c18f","source":"amazon-inspector","versions":["1.0.1"]},{"modified_time":"2026-08-04T22:05:34Z","sha256":"730baa19026e3249c382e37bac44b63c49d3ba19bf587fbe22fa4ae4118140f4","source":"amazon-inspector","versions":["1.6.9"],"id":"IN-MAL-2026-011327","import_time":"2026-08-04T22:30:11.103477673Z"},{"sha256":"839c397fbfc37cc55353b7df0211f5e53ad1445f638cef6e4a7e91bb716b049b","source":"amazon-inspector","versions":["1.0.5"],"id":"IN-MAL-2026-011329","import_time":"2026-08-04T22:30:11.173671383Z","modified_time":"2026-08-04T22:05:49Z"},{"modified_time":"2026-08-04T22:06:07Z","sha256":"458757b4c185e84321b45bd7fec158459300d68106826e5774df2399818c7916","source":"amazon-inspector","versions":["1.9.1"],"id":"IN-MAL-2026-011331","import_time":"2026-08-04T22:30:11.279991159Z"},{"import_time":"2026-08-05T03:11:16.336939362Z","modified_time":"2026-08-05T01:42:52Z","sha256":"c49951bbd2d5903fcfbfd539e209d9e1ecb2ce7d4a654d9a0135b50447b72ce6","source":"amazon-inspector","versions":["1.6.6"],"id":"IN-MAL-2026-011515"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/osinthell/v/1.9.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/osinthell/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/osinthell/v/1.6.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/osinthell/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/osinthell/v/1.9.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/osinthell/v/1.6.6"}],"affected":[{"package":{"name":"osinthell","ecosystem":"npm","purl":"pkg:npm/osinthell"},"versions":["1.9.5","1.0.1","1.6.9","1.0.5","1.9.1","1.6.6"],"database_specific":{"indicators":{"package_integrity":[{"filename":"osinthell-1.9.5.tgz","hashes":{"sha512_sri":"sha512-U/aYCDVY9sh/f3iATst+mq+08aE3spNPeiemK0DswRKhi11ny6ULlLkL5jjvX/UlV8fOLv0/XLz92NDeugnqRQ==","sha1":"c655ca0b11a34ff359aabc2d8819b7c5b6e5475e"}}],"evidence_files":[{"sha256":"496af023249908c73005235c7aa348a1604ec70c6b13b07eb30641908b4a207e","tlsh":"405165119e63f2559d906ed9a338c512f8d7603eb3ce06c3f69937e699540940a01c37","path":"index.js"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/osinthell/MAL-2026-11542.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}