{"id":"MAL-2026-12128","summary":"Malicious code in aasp-tent-aasp-tent-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8f40a1f6a1ee90eed076db7cd24155d8dd0ceb6f3bd3b0698eb9ff0b0543efee)\nOn require of the package, index.js loads _compat.js, which detects the host OS/arch and fetches a per-platform native binary from author-controlled hosts whose names are assembled at runtime via array.join(\"\") to hide them from static scanners: oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, with a DNS TXT fallback across tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site (base64 chunks reassembled from TXT records). The downloaded bytes are written under disguised names into /var/tmp or %TEMP% (e.g., dotnet_diag_\u003chex\u003e.exe,.cache_\u003chex\u003e), chmod 0755, and detached-spawned via cp.spawn(\"/bin/sh\", [\"-c\", path+\" &\"]) or cmd.exe /c start /b, yielding remote code execution on the installer's machine at import time. A second module lib/telemetry.js ships a near-identical dropper primitive (require(\"child_\" + \"process\"), os[\"host\" + \"name\"](), fs[\"chmod\" + \"Sync\"], base64 decode + chmod 755 + spawn /bin/sh) that is not currently referenced by index.js but is staged for activation. The package is advertised as a \"platform core\" but ships no functionality matching that description; its only import-time effect is the binary drop-and-exec chain.\n","modified":"2026-08-05T10:05:42.172227835Z","published":"2026-08-05T09:10:28Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T09:10:49Z","sha256":"8f40a1f6a1ee90eed076db7cd24155d8dd0ceb6f3bd3b0698eb9ff0b0543efee","source":"amazon-inspector","versions":["0.0.2"],"id":"IN-MAL-2026-014578","import_time":"2026-08-05T09:28:27.300942553Z"},{"id":"IN-MAL-2026-014576","import_time":"2026-08-05T09:28:27.12576392Z","modified_time":"2026-08-05T09:10:28Z","sha256":"d58c21b32e0af7aee23f57ab94f87e6ea6a7fa8ff31efacdae2d5ebca6e94ceb","source":"amazon-inspector","versions":["33.4.6"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/aasp-tent-aasp-tent-core/v/0.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/aasp-tent-aasp-tent-core/v/33.4.6"}],"affected":[{"package":{"name":"aasp-tent-aasp-tent-core","ecosystem":"npm","purl":"pkg:npm/aasp-tent-aasp-tent-core"},"versions":["0.0.2","33.4.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"f9a18696066a702987b09be4c7174416f65ae26333908294f75c99885f7703483b1efc","path":"_compat.js","sha256":"44f31f3aa4d5fbb291c8c65237b4a198364aa93e3550e2c9971164a531c4b78b"}],"package_integrity":[{"filename":"aasp-tent-aasp-tent-core-0.0.2.tgz","hashes":{"sha1":"53ad8e31410cc63f4f5e8f2a3c698854b0a205b7","sha512_sri":"sha512-zOpCQf+Ty5+Ei0WtOrBePODzEPBnP+OM/xKlzrB1mdoq77zIIesSRj0jqztiwwQhd+UblkVVgSnRlfyXv7WUVA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/aasp-tent-aasp-tent-core/MAL-2026-12128.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}