{"id":"MAL-2026-12369","summary":"Malicious code in elephant-array-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d2cfcddc59bba26e90415bf89488d4a814e5c1db07091da5e46b07f7727e49bb)\nindex.js is a heavily obfuscated (obfuscator.io: rotated string array + RC4 decoder, control-flow flattening, hex literals) top-level IIFE with no functionality matching the advertised 'array utils' purpose. On require(), it constructs a hardcoded IPv4 address by concatenating four numeric literals, performs an https.get against that host, splits the response on ':' to obtain an IV and ciphertext, decrypts the payload with createDecipheriv using a Buffer-keyed cipher, writes the plaintext to a file under the current working directory, and executes it via child_process.exec with windowsHide:true. This is a canonical remote-payload dropper: any installer that requires the package hands arbitrary-code-execution to whoever controls the hardcoded IP. The obfuscation layer exists to hide the exfil/dropper URL, decryption key and command from static inspection. The generic package name is consistent with a typosquat lure.\n","modified":"2026-08-05T13:35:21.723046590Z","published":"2026-08-05T12:32:11Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T13:08:38.263259989Z","modified_time":"2026-08-05T12:32:11Z","sha256":"d2cfcddc59bba26e90415bf89488d4a814e5c1db07091da5e46b07f7727e49bb","source":"amazon-inspector","versions":["1.0.6"],"id":"IN-MAL-2026-014695"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/elephant-array-utils/v/1.0.6"}],"affected":[{"package":{"name":"elephant-array-utils","ecosystem":"npm","purl":"pkg:npm/elephant-array-utils"},"versions":["1.0.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"d8616aaa40456633d7f26198e95be9544f4036f6bb01637b0c1fc976d60004c9","tlsh":"2db296c83fc1b0941623b0f76e1b6595e1396c89b28c9449f7a7b068fe18718e476f68"}],"package_integrity":[{"hashes":{"sha1":"bbdc393edf85170143540f78aa0ddea4c6cfb63e","sha512_sri":"sha512-1Oxnhdr7mQjRuBztPvWiIHIui/fPIT6j8elW5oZiY4Yo/kfBtM9g09j7XKZfTPN0EO5aWLrfDvIshLT5T4AltA=="},"filename":"elephant-array-utils-1.0.6.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elephant-array-utils/MAL-2026-12369.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}