{"id":"MAL-2026-15632","summary":"Malicious code in node-request-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0832f8d4554223aaaf958a5f008faa621b29c39f428c4fb042c084c05c4c7cef)\nOn npm install, package.json's postinstall runs index.js, which on Windows hosts downloads a JavaScript payload from https://limbomail.com/api/attachment/l4TIRPOsaUxR._603-vhKDRdgKl3RalN_TVUZYGPsJy2Y/all.js (TLS verification disabled), writes it as winsvc.js under APPDATA, and executes it via wscript/node. The dropper installs multiple Windows persistence mechanisms — HKCU Run key, UserInitMprLogonScript, a scheduled task at \\Microsoft\\Windows\\Shell\\WinSvcHost, and a Startup folder.lnk pointing at a hidden VBS launcher — and re-checks the remote URL for updated payloads roughly every two hours. The install path uses -EncodedCommand PowerShell (UTF-16LE base64) with hidden-window flags and an AMSI bypass via amsiInitFailed reflection, and aborts on CI environments, low-CPU/low-memory hosts, and hostnames/usernames matching sandbox keywords (sandbox|virus|malware|sample|analysis|cuckoo|anyrun|hybrid) to evade analysis. index.js additionally sets Hidden/System file attributes on its dropped artifacts.\n","modified":"2026-08-31T18:31:23.140760225Z","published":"2026-08-31T18:02:18Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-019303","import_time":"2026-08-31T18:22:29.429914667Z","modified_time":"2026-08-31T18:02:18Z","sha256":"0832f8d4554223aaaf958a5f008faa621b29c39f428c4fb042c084c05c4c7cef","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/node-request-utils/v/1.0.0"}],"affected":[{"package":{"name":"node-request-utils","ecosystem":"npm","purl":"pkg:npm/node-request-utils"},"versions":["1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"a55bd4402f47b070c308b0d4bac1a90a51c0fba62e78d9ff3938efd33b89446b","tlsh":"a4d10a79a2f14a33d2d266e461134b27a9f32213b50bc150f56cd989af45394c1e73fe","path":"index.js"}],"package_integrity":[{"filename":"node-request-utils-1.0.0.tgz","hashes":{"sha1":"b613f0c3b357bff9245d5f9e9cec6564bf956813","sha512_sri":"sha512-SbvF+pYkObbGuMQBoeffU/e3H2kjySXwPmNfxn5f8sL8JuWKyVkAJxZdzGxDzOvawN9+J5c6yxmc7lConlhMyA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/node-request-utils/MAL-2026-15632.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}