{"id":"MAL-2026-14142","summary":"Malicious code in testingsmthb1g (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (04fa6b8b5826315448e5d4f27036ab31ef115621027c040897e200894c43dfa3)\nscripts/postinstall.js runs at npm install and performs an install-time dropper chain. A URL stored as an integer array is XOR-decoded (key 'stf2026') to https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe — a personal GitHub account unrelated to the package publisher, at a random-named repository with a mutable 'null' release tag. On Windows, the script downloads this binary to the TEMP directory and spawns it detached with stdio ignored. On WSL/virtualized Linux, the script detects the environment via /proc/version and WSL_DISTRO_NAME, assembles an XOR-decoded PowerShell command line, and executes it via exec() to fetch and run the same payload on the Windows host, escaping the Linux sandbox. In parallel, the script POSTs a platform label to a hardcoded bare-IP endpoint http://193.70.34.101:20099/vote whose hostname is constructed via split-join to evade string matching. The destination URL, PowerShell command, and shell fragments are all XOR-obfuscated integer arrays reconstructed at runtime.\n","modified":"2026-08-18T23:45:11.530574347Z","published":"2026-08-18T23:26:01Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-018196","import_time":"2026-08-18T23:41:22.873486589Z","modified_time":"2026-08-18T23:26:01Z","sha256":"04fa6b8b5826315448e5d4f27036ab31ef115621027c040897e200894c43dfa3"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/testingsmthb1g/v/1.0.0"}],"affected":[{"package":{"name":"testingsmthb1g","ecosystem":"npm","purl":"pkg:npm/testingsmthb1g"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"scripts/postinstall.js","sha256":"e3ce3954c445e7e18a648de2f242ee382e2a55971e97ed6a931204b5422a880b","tlsh":"2ed13fca1ef590348347f96884cf9d13b2a6c207320d4a65ff8f41107f5793c85a69e9"}],"package_integrity":[{"filename":"testingsmthb1g-1.0.0.tgz","hashes":{"sha1":"22ba20d1d59b3594ec08464be3e907e75d15e8c2","sha512_sri":"sha512-6v0oj75/3JGOw6QPpf4qDqX8JJHsEKWL6TxXhfLw9qxtg3dApvWHmERGHFsGNZlEiHG9G9QyU20rmgWFnZP4ZQ=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/testingsmthb1g/MAL-2026-14142.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}