{"id":"MAL-2026-12357","summary":"Malicious code in cors-security (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b1cff2c95bb175e36d5cb7a6e4880ed0f8816cbfb1dc7acef5d8173cf2cc40bb)\nThe CommonJS entry point of cors-security@1.0.1 exposes a getPlugin() API that issues an HTTPS GET to the hardcoded host workconfig.vercel.app and passes the response body directly to new Function('require', data)(require), running attacker-controlled JavaScript inside the consumer's Node process with access to require. TLS certificate verification is disabled on that request (rejectUnauthorized: false). The remote-loader code is present only in the CJS entry and absent from the ESM variant, and does not relate to the package's advertised SVG-utility purpose (name svgcraft, description \"Professional zero-dependency SVG utilities\"). Any consumer that requires the package and invokes the returned function executes whatever content the operator of workconfig.vercel.app serves at that moment.\n","modified":"2026-08-05T13:35:15.164057646Z","published":"2026-08-05T12:57:59Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T12:57:59Z","sha256":"b1cff2c95bb175e36d5cb7a6e4880ed0f8816cbfb1dc7acef5d8173cf2cc40bb","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-014827","import_time":"2026-08-05T13:08:49.574039087Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/cors-security/v/1.0.1"}],"affected":[{"package":{"name":"cors-security","ecosystem":"npm","purl":"pkg:npm/cors-security"},"versions":["1.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"d10274287cf364920b63709d45cb909c74b6e507305bda50ea6c49012fa87ace1f7afd","path":"src/index.cjs","sha256":"9d418c7b6dc5ddb393c8622f2af4cf3833869b7c8ff36bf774b40853b6ffe778"},{"tlsh":"10117200d2aa1e0310cae9a16c6d469aa031880749947d2637cf4a7c1fcca7f21fe2bd","path":"package.json","sha256":"8e8c4dc00e7effac49b42385c4e9db0ed9f2e7689190ca1f492470611927ef25"}],"package_integrity":[{"hashes":{"sha1":"c618a93fedecf07794ee5e53e2f805f2c50b12cd","sha512_sri":"sha512-PvTw8fjG+HQk063OFfUXj4b2LE/F4e+IElRm/a+SsJmaILZ8d0/MlgjE4S4f3RB8rNmvwGTXnkIg2CTecESbyg=="},"filename":"cors-security-1.0.1.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cors-security/MAL-2026-12357.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}