{"id":"MAL-2026-12190","summary":"Malicious code in retracfix (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7656b934d52c542162613f35aa909400f46aa0dae186ef9d55667f048bdfdcd4)\nThe npm package retracfix@1.0.0 ships with no documented functionality (empty description, no README, no source, no dependencies) and consists only of postinstall.js plus a single Windows PE at bin/ezfn.exe. package.json declares scripts.postinstall='node postinstall.js' and os=['win32']; postinstall.js enumerates bin/ for any.exe and unconditionally runs it via execFileSync on Windows installs. The bundled ezfn.exe is a.NET assembly whose metadata contains the type/member signatures of a remote-control agent and infostealer: ClientSocket / ConnectServer / BeginConnect / isConnected / ActivatePong for a C2 socket; SendBot / ChatID plus WebClient.DownloadString for a Telegram-bot exfil/command channel; ManagementObjectSearcher with the strings 'Antivirus' and 'Exclusion' for AV enumeration and Defender-exclusion registration; avicap32.dll for webcam capture; Microsoft.Win32 RegistryKey / CurrentUser Run-key persistence; WindowsIdentity/WindowsPrincipal privilege checks; SymmetricAlgorithm CreateEncryptor/Decryptor, WriteAllBytes, GetTempPath, InstallDir/InstallStr/LoggerPath; and a 'Spread' routine. The package name plus the binary name 'ezfn' (Easy Fortnite) fit a gaming-cheat lure. Running `npm install retracfix` on Windows drops and launches this binary, handing persistent remote control of the installer's host to the operator.\n","modified":"2026-08-05T10:06:14.400221430Z","published":"2026-08-05T08:55:31Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-014476","import_time":"2026-08-05T09:28:16.487449112Z","modified_time":"2026-08-05T08:56:01Z","sha256":"15feec56f800e0a120a9d99df2755c5ed5a92c42a0a0f4207bcb6304ae8a9fee","source":"amazon-inspector"},{"modified_time":"2026-08-05T08:55:31Z","sha256":"7656b934d52c542162613f35aa909400f46aa0dae186ef9d55667f048bdfdcd4","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-014473","import_time":"2026-08-05T09:28:16.186108471Z"},{"versions":["1.0.3"],"id":"IN-MAL-2026-014474","import_time":"2026-08-05T09:28:16.273395321Z","modified_time":"2026-08-05T08:55:40Z","sha256":"686e52b984e09e4bae909382a250db5acc1eda2e48a24c6af0083d15fdd82983","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/retracfix/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/retracfix/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/retracfix/v/1.0.3"}],"affected":[{"package":{"name":"retracfix","ecosystem":"npm","purl":"pkg:npm/retracfix"},"versions":["1.0.1","1.0.0","1.0.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/retracfix/MAL-2026-12190.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"retracfix-1.0.1.tgz","hashes":{"sha512_sri":"sha512-FcNaQUzZWm/kszSRHxT1PtxKiZU0tnXGJK4wd+VMFcKKZ90dkdtlf4J/U+Np1E8fgr19+XF4wpmMffd/gfl5FQ==","sha1":"4a4d860866920cfe8563f7e05bbd1b5525d18762"}}],"evidence_files":[{"sha256":"037f7cd6f40e0baf8de373c00d29f9f238e5f51cd2e9f92d10554dd7dd49225b","tlsh":"6cf0dd804eeb5a2a55b140c1ff2d21372c4f8c20b30df060c1ac864857410ac95db7c9","path":"postinstall.js"},{"sha256":"418e262088eb5f3ba30cd456c775a607232d0d148c2aa20fe0e10433016cb681","tlsh":"19b34b4efb458a08c15d0e778563658a82fac867e927f76f25cc1eda8d618ccc9cf484","path":"bin/ezfn.exe"},{"sha256":"def974d2ced7714fdc59caa9d12e02c79c914a8a9c1c41542bd0e24451747f02","tlsh":"0ad01200c8614f3278d87fad0c27909da5310d4b44853d2963db698c4b5a6ba98bf27a","path":"package.json"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}