{"id":"MAL-2026-15565","summary":"Malicious code in @testrelic/playwright-analytics (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c305bbe247587c98b06f039cdcf78066dbcd4fdacf5a5de0411023c2a4fcc97a)\nscripts/postinstall.cjs is registered as the package's postinstall lifecycle script and runs automatically on `npm install`. After a block of legitimate-looking config-scaffolding code, the file contains roughly 7 KB of whitespace padding followed by an obfuscated payload that reconstructs a large string via a custom Fisher–Yates shuffle, resolves the String `constructor` property (Function) to avoid any literal `Function`/`eval` token, and invokes `Function('', decodedBody)(decodedArg)`. Immediately before the invocation the script assigns `require`, `module`, `__dirname`, and `__filename` onto the global object so the decoded body can load arbitrary Node built-ins. The whitespace gap conceals the payload from casual review of the file, and the indirection through `String[constructor]` avoids the literal tokens static reviewers grep for. The bundled `dist/index.cjs`, `dist/reporter-entry.cjs`, and `dist/cli.cjs` additionally contain `require('child_process')` alongside outbound HTTP POST call sites and `ping` invocations. The package's declared identity (a Playwright analytics reporter under an unfamiliar `@testrelic` scope) is inconsistent with shipping an obfuscated postinstall dynamic-code loader.\n","modified":"2026-08-29T03:30:10.362818188Z","published":"2026-08-29T03:00:52Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-29T03:00:52Z","sha256":"c305bbe247587c98b06f039cdcf78066dbcd4fdacf5a5de0411023c2a4fcc97a","source":"amazon-inspector","versions":["2.13.0"],"id":"IN-MAL-2026-019149","import_time":"2026-08-29T03:19:44.702034358Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@testrelic/playwright-analytics/v/2.13.0"}],"affected":[{"package":{"name":"@testrelic/playwright-analytics","ecosystem":"npm","purl":"pkg:npm/%40testrelic/playwright-analytics"},"versions":["2.13.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@testrelic/playwright-analytics/MAL-2026-15565.json","indicators":{"evidence_files":[{"tlsh":"84127e555a8f573946e2e6c6d52e0363f673e2b6369ca3a0b0edf0c85b91010197368f","path":"scripts/postinstall.cjs","sha256":"19795496ad752f37b76a2dd5d6c6a2914ab6fa62bda0bda7bfe5cd4afd9f029f"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-sdKejYN3QLQHkj0HILr+UU9uFT60clNsKk33e0B85ODjySausezaa2ypIJ6Mo26j45y+02J/zIJei50jxMo1nQ==","sha1":"dc5200d7950f32305ec324c48170a9764e4534d7"},"filename":"playwright-analytics-2.13.0.tgz"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}