{"id":"MAL-2026-12335","summary":"Malicious code in aegis-runtime (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a66d1f02c3c943836d41a7ec92c150c5529880890a4cc502115412dddb0c519c)\nThe package's declared postinstall hook runs `node src/test.js`, which issues an HTTPS GET to https://workconfig.vercel.app with TLS certificate validation disabled (`rejectUnauthorized: false`) and passes the response body to `new Function('require', data.toString())(require)`, executing the fetched payload with access to the installer's `require` at `npm install` time. The destination is a mutable, non-registry, non-publisher host unrelated to the package's advertised purpose. Package metadata presents the module as a Node.js runtime monitoring and diagnostics toolkit and lists the placeholder author `Your Name`; the postinstall behavior is unrelated to the advertised monitor sources.\n","modified":"2026-08-05T13:34:55.827494146Z","published":"2026-08-05T12:25:07Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014647","import_time":"2026-08-05T13:08:33.518849833Z","modified_time":"2026-08-05T12:25:07Z","sha256":"a66d1f02c3c943836d41a7ec92c150c5529880890a4cc502115412dddb0c519c","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/aegis-runtime/v/1.0.0"}],"affected":[{"package":{"name":"aegis-runtime","ecosystem":"npm","purl":"pkg:npm/aegis-runtime"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"aegis-runtime-1.0.0.tgz","hashes":{"sha1":"f4b47005943a26a119bfee1da5ed0da2a88b9ef9","sha512_sri":"sha512-iJLIeMyWH5bUeiPfDAuRIlA9AU2+lenR7WSZlLdpT9FpUHt177V+kPUyCdIBII7ql3lqFjUVQ64BXghX1Wkevw=="}}],"evidence_files":[{"path":"src/test.js","sha256":"58137ca700a9a27ce27e2c6b04a5f8a7f0ba6f1d91f04689b98d65e0024e8052","tlsh":"d2d0a7f93288913e390161e88206f40dc137d211735192e7c10852a046a64b87193be1"},{"sha256":"7b94700f0dc4cd243185e648950cbb8677eb60416fce630f34f75fdb5ff6af67","tlsh":"73114834cda80d231ed43fa6a8692486f662885b8e647c0db7d7057c4b8e07b11ff22c","path":"package.json"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/aegis-runtime/MAL-2026-12335.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}