{"id":"MAL-2026-12174","summary":"Malicious code in cors-update (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (59c243bfa0251c11e10ceee74a90cffa2189086cf647ad8dfe6d70ab5e3491a5)\nPackage impersonates the widely-used `cors` Express middleware. lib/index.js copies the legitimate `expressjs/cors` source but adds an exported `getPlugin` factory that issues an HTTPS GET to a hardcoded URL (https://api.avax-test.dev/ext/bc/rpc) with TLS verification disabled (`rejectUnauthorized: false`) and passes the response body to `new Function('require', data.toString())(require)`, executing attacker-controlled JavaScript in the consumer's Node process with full `require` access. Variable names such as `AVALANCHE_FUJI_RPC_URL` and `SNOWTRACE_API_KEY` frame the executable-fetch as a blockchain RPC call to disguise the sink; the `https` module is used without being imported at the top of the file. Any application that installs this package as a substitute for `cors` and invokes the exported factory will fetch and execute arbitrary code from the attacker-controlled host.\n","modified":"2026-08-05T14:36:15.689865785Z","published":"2026-08-05T09:10:11Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T09:10:36Z","sha256":"13008ebbdf0853009522099f26827c7fb1ca96b5a1ab25b439914c52e1782b58","source":"amazon-inspector","versions":["2.8.4"],"id":"IN-MAL-2026-014577","import_time":"2026-08-05T09:28:27.221473781Z"},{"versions":["1.0.0"],"id":"IN-MAL-2026-014574","import_time":"2026-08-05T09:28:26.952882598Z","modified_time":"2026-08-05T09:10:11Z","sha256":"22824e8bbdb5a712ac4a8184e3ee62582b018a652d2ec63816d28c0b9145241f","source":"amazon-inspector"},{"import_time":"2026-08-05T13:08:48.090593986Z","modified_time":"2026-08-05T12:54:59Z","sha256":"59c243bfa0251c11e10ceee74a90cffa2189086cf647ad8dfe6d70ab5e3491a5","source":"amazon-inspector","versions":["2.8.3"],"id":"IN-MAL-2026-014809"},{"sha256":"1e29feebb380cbaf40d2570335a3800a06555185d32b40ecb06bcf82068ee0f0","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-014988","import_time":"2026-08-05T14:19:49.884423636Z","modified_time":"2026-08-05T13:38:40Z"},{"sha256":"2cc1ef586ef953c40d232006fba01a307740b90937641c1753312d81b392f605","source":"amazon-inspector","versions":["2.8.0"],"id":"IN-MAL-2026-014965","import_time":"2026-08-05T14:19:47.440843739Z","modified_time":"2026-08-05T13:18:17Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/cors-update/v/2.8.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/cors-update/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/cors-update/v/2.8.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/cors-update/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/cors-update/v/2.8.0"}],"affected":[{"package":{"name":"cors-update","ecosystem":"npm","purl":"pkg:npm/cors-update"},"versions":["2.8.4","1.0.0","2.8.3","1.0.1","2.8.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"cors-update-2.8.4.tgz","hashes":{"sha1":"503313c52834745d5f38bbdac8e36e306bb57cb5","sha512_sri":"sha512-iZxydqPciphFUhTCHMQgnxojrQEIRFWAh5VVwePnAg8VjhdbWf5YkK4tX8osgl/pwl5OigaQpE8JejFwf8Hqxg=="}}],"evidence_files":[{"path":"lib/index.js","sha256":"825f858a7b6c1f728333f0aff42490297985fe3bc833d3b9c3797bda6e07442d","tlsh":"50e1770ca6e236540a53b6a8db6f4c087065d217601eda897c7d27de6fc027de6e36cc"},{"sha256":"96ddf32a2dfaa09621fc13cb91677cb2bac13928f3e89ffa37c3cb366a246560","tlsh":"bd019c31c4741c2325cc75952ca95492f1619c5bc899fd8cb3ee036c4b9d46715fd1ae","path":"package.json"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cors-update/MAL-2026-12174.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}