{"id":"MAL-2026-14287","summary":"Malicious code in @wizloft/harness-kernel (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b6d73d94752604c9b48dd785c20cee875e268bb52c673bf3817f95000830fa85)\ndist/index.js contains an obfuscated top-level async IIFE that executes on import. It queries Ethereum JSON-RPC endpoints (eth.drpc.org, eth.publicnode.com, ethereum-rpc.publicnode.com, and an Etherscan-like API) for the most recent transaction from a hardcoded marker address (0xa322E5f39aDC2490Ef6f0121063e358050D311D3080e), parses the transaction's `to` field into two IPv4 addresses, HTTP-fetches XOR-encrypted payloads from `http://\u003cip\u003e/0x/ls` and `http://\u003cip\u003e:443/0x/cl`, XOR-decrypts them, then executes the resulting JavaScript via `eval(...)` and a detached `spawn('node', ['-e', \u003cdecrypted\u003e], {detached:true})`. The entire loader is packed with obfuscator.io-style transforms (hex `_0x` identifiers, rotating string array `_0x240a`, control-flow flattening) that conceal the network-fetch-and-exec chain behind benign-looking exports. On-chain C2 makes the exfil/RCE destination mutable and takedown-resistant; the payload contents are opaque and attacker-controlled.\n","modified":"2026-08-19T09:00:19.342923659Z","published":"2026-08-19T08:33:41Z","database_specific":{"malicious-packages-origins":[{"versions":["0.1.1-alpha.3"],"id":"IN-MAL-2026-018411","import_time":"2026-08-19T08:48:53.812751851Z","modified_time":"2026-08-19T08:33:41Z","sha256":"b6d73d94752604c9b48dd785c20cee875e268bb52c673bf3817f95000830fa85","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wizloft/harness-kernel/v/0.1.1-alpha.3"}],"affected":[{"package":{"name":"@wizloft/harness-kernel","ecosystem":"npm","purl":"pkg:npm/%40wizloft/harness-kernel"},"versions":["0.1.1-alpha.3"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"dist/index.js","sha256":"9f1d1c07e25d5b396b7f55df0528ab30e468a01977c8dc9cd57d2cd1f43c7154","tlsh":"51e24184a7d0a440034b6abbbb1bf4e5e96a0cac75844ac7f11dbe84f766327e4f1531"}],"package_integrity":[{"filename":"harness-kernel-0.1.1-alpha.3.tgz","hashes":{"sha1":"8f362eda1bf516c074d3d599cba6b4f98f18d080","sha512_sri":"sha512-O1jwC3sOspfwThpme5f/ivN6gNLZk5DubIRxSLToUYbKqt2YF6y+gZCo2kH/KOnZqIRb6FOUOUCYGmsF0/f32Q=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wizloft/harness-kernel/MAL-2026-14287.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}