{"id":"MAL-2026-13879","summary":"Malicious code in dakumangalsingh (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (502c2aae77a471762612a5114d299651b7e75571d5c6d9dd5665a3dc2c503327)\npackage.json declares a postinstall hook that executes a bundled Windows PE launcher (DakuMangalSingh\\DakuMangalSingh.exe) at npm install time. The launcher is a jpackage wrapper that loads an embedded JAR named virus.jar containing classes Main, Executor, BatchExecutor, Fetch, RobotService (java.awt.Robot input synthesis), Screenshort (screen capture), and DeviceId (host fingerprinting) — the shape of a remote-command agent with screen-capture and input-synthesis capability. A bundled replicate.bat installs persistence by creating a shortcut to the dropped executable in %APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup so the payload auto-runs at every user logon. A cleanup.bat kills the process and recursively deletes the package folder, providing anti-forensics on the installer's host. Installing the package on Windows results in immediate arbitrary code execution, a persistent logon-triggered agent, and evidence-removal tooling — with no legitimate library functionality.\n","modified":"2026-08-14T14:46:35.906534558Z","published":"2026-08-12T12:39:55Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017568","import_time":"2026-08-12T12:51:50.851510999Z","modified_time":"2026-08-12T12:39:55Z","sha256":"502c2aae77a471762612a5114d299651b7e75571d5c6d9dd5665a3dc2c503327","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-017571","import_time":"2026-08-12T12:51:51.065941481Z","modified_time":"2026-08-12T12:40:20Z","sha256":"89cca10a1d7b205f9caecd1294b9aed12a6eb781599d8b90a854f9fb2c169f2d","source":"amazon-inspector","versions":["1.0.0"]},{"source":"amazon-inspector","versions":["1.1.0"],"id":"IN-MAL-2026-017570","import_time":"2026-08-12T12:51:51.017539209Z","modified_time":"2026-08-12T12:40:11Z","sha256":"7c6c4376c4b5056a3784ff7a88906659e085c3da56bcd17d445f57e257cbd937"},{"id":"IN-MAL-2026-017752","import_time":"2026-08-14T14:28:05.881686754Z","modified_time":"2026-08-14T14:10:58Z","sha256":"948cec286902bdae073ea3a4dbef22a9030ba0ae3003046230445d5c86051c3d","source":"amazon-inspector","versions":["2.0.1"]},{"source":"amazon-inspector","versions":["1.2.0"],"id":"IN-MAL-2026-017756","import_time":"2026-08-14T14:28:06.302812141Z","modified_time":"2026-08-14T14:11:33Z","sha256":"a554a197c45fc7c8bd2d2ea4a771a6f1268c35a4c021011ba44e3fc4bcde6e07"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dakumangalsingh/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/dakumangalsingh/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/dakumangalsingh/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/dakumangalsingh/v/2.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/dakumangalsingh/v/1.2.0"}],"affected":[{"package":{"name":"dakumangalsingh","ecosystem":"npm","purl":"pkg:npm/dakumangalsingh"},"versions":["1.0.1","1.0.0","1.1.0","2.0.1","1.2.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dakumangalsingh/MAL-2026-13879.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"dakumangalsingh-1.0.1.tgz","hashes":{"sha1":"6dfeefa39eb46fbeb62d33f2bdbc69cffc376b60","sha512_sri":"sha512-cgiyZ4LaBw3uMuagUQtBFjQbv3NC6apzy643rwgPFPGsvu/s1HQlSXo9UMGQuhkQBKvfnVPMqhkjJcfrPyD+Gg=="}}],"evidence_files":[{"sha256":"0b17ae0e0441639b3029a9cd91b887e4f43b9ff5bb0f8cfec141250e33e68ec7","tlsh":"dbd0a722884072336870cb540861064677354f1f34344c067fb7154891d36b608d4b06","path":"package.json"},{"sha256":"8ab43c718b2ac659b35ee28a898601ab7d69ed8c634585538100152fb899e420","tlsh":"af52bf757dc3a86dfd1bb039c166e0078c2ec1d51e2fb20369aa2c6715b492c871de8d","path":"DakuMangalSingh/app/virus.jar"},{"path":"replicate.bat","sha256":"4bae43afe800291e1991cdb81d7945967c372309245f7f69a9a78b7a4284ec06","tlsh":"9511e131f015e395a2359e4548b85948fa9f44cf1316dc95b809c86daf187cb59fc1c3"},{"tlsh":"5241fd893585762a07738ac09e6010a5fa8c8a6f42752d9d34adc5b02f583c10fff2cd","path":"cleanup.bat","sha256":"cc0381edf2e467687359d1788fac74f46b543859b50130c87d5c7b849d744715"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}