{"id":"MAL-2026-14211","summary":"Malicious code in sw-pluginer (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (38427a19b5e267273200d4dc05d0b9a60f0a38bfe7916adaaeb90338af5f1b06)\nsw-pluginer presents itself as a Tailwind plugin for service worker registration, but its main export — invoked when Tailwind processes its config via require('sw-pluginer') — reads a URL from a staged file at node_modules/.bin/manifest.json, performs an HTTP GET to that URL, and passes the response body directly to eval() in the Node build process. The staging file is written by a separate dropper component and is unlinked after being read, hiding the payload destination from static inspection of the sw-pluginer tarball itself. The fetched code is not pinned, hashed, or signature-verified, and it is executed in the developer's Node environment (not in a browser as service worker code) — so whoever controls the staged manifest.json obtains arbitrary code execution on the developer machine at build time. The self-deleting indirection through node_modules/.bin/manifest.json plus eval of unverified network-fetched JavaScript is a covert dropper mechanism, not service worker registration.\n","modified":"2026-08-19T03:00:14.567212331Z","published":"2026-08-19T02:49:26Z","database_specific":{"malicious-packages-origins":[{"sha256":"04cb9419a7170f7f1d55a8515c8d931d0a388fdf9b55c692a72a3f447539b650","source":"amazon-inspector","versions":["1.1.0"],"id":"IN-MAL-2026-018301","import_time":"2026-08-19T02:57:22.208634612Z","modified_time":"2026-08-19T02:49:34Z"},{"modified_time":"2026-08-19T02:49:26Z","sha256":"38427a19b5e267273200d4dc05d0b9a60f0a38bfe7916adaaeb90338af5f1b06","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-018300","import_time":"2026-08-19T02:57:22.12018987Z"},{"modified_time":"2026-08-19T02:50:02Z","sha256":"4774f9e54911d1231788224ac0d528431050050cbcc8a053f1f40eb6e73b8ff1","source":"amazon-inspector","versions":["1.2.0"],"id":"IN-MAL-2026-018304","import_time":"2026-08-19T02:57:22.516514813Z"},{"versions":["1.0.1"],"id":"IN-MAL-2026-018303","import_time":"2026-08-19T02:57:22.424629099Z","modified_time":"2026-08-19T02:49:50Z","sha256":"b5f6a7d297091f57fe43af57f951f3acc3f82e51363747e84b87113c13e76212","source":"amazon-inspector"},{"sha256":"cc3a59d3a151fdca61663452e132622d9f9201013e53a4f57805845c290c5551","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-018302","import_time":"2026-08-19T02:57:22.332600519Z","modified_time":"2026-08-19T02:49:41Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/sw-pluginer/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sw-pluginer/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sw-pluginer/v/1.2.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sw-pluginer/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sw-pluginer/v/1.0.0"}],"affected":[{"package":{"name":"sw-pluginer","ecosystem":"npm","purl":"pkg:npm/sw-pluginer"},"versions":["1.1.0","1.0.2","1.2.0","1.0.1","1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"ca164ecc2344c5ce1f3ad4e4c75cea4b0fa4c9560f564d59858062d342c93747","tlsh":"b301feaacd81e437057125611806c314e0b7812482239091f3ec93d65ffbc2cd73bcc0","path":"lib/register-worker.js"},{"tlsh":"2b21e4924fdc4997187312905b3b9213e17ec16a6112c2907abf43d53fd302081354fc","path":"index.js","sha256":"834c8ecadebf0420243421df5d4c24e0dc6cb84fec2c6bbdbea81d99b8cbf657"}],"package_integrity":[{"filename":"sw-pluginer-1.1.0.tgz","hashes":{"sha1":"930c0a7ce78cca8b8db4bbcef5dd7320a7594d26","sha512_sri":"sha512-MMl1pB9cg2gUGlHc5JJUi5s7Qw78aXNr1R3TocPzjYmY5T0e2lB74N1F5Dd00N3IB3E/o52AIEUGJH58Lz2oow=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sw-pluginer/MAL-2026-14211.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}