{"id":"MAL-2026-15916","summary":"Malicious code in xcryption (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (989e6d862a8e433df7f0bd31ab9a6b76f616273783517c81f5e428ad2774ad4e)\nThe package declares a postinstall script (scripts/install.js) that on npm install downloads a ZIP archive from https://www.dropbox.com/scl/fi/djz38wdi1wks9j1h57zuv/coeur.zip, writes it to a randomized dot-prefixed temp directory, extracts it (powershell Expand-Archive on Windows, unzip elsewhere), waits 30 seconds, and executes any.exe/.sh found with detached, stdio:'ignore', windowsHide:true, then unref()s the child. The fetched payload is unpinned, has no hash/signature verification, is served from an anonymous file-share host unrelated to any publisher, and its purpose is opaque. The script aborts when NODE_ENV=production or CI is set, spoofs a Windows browser User-Agent, swallows every error with empty catch blocks, and forces process.exitCode=0 so install always reports success. Package identity is inconsistent: package.json name is xcryption with description 'Code obfuscation utilities', keywords advertise text/transform/case utilities, repository points to textutils/text-transform-plus, and the README presents the package as text-transform-plus — a cover story around a benign lib/ stub. Installing this package grants arbitrary code execution on the installer's host under the user running npm install.\n","modified":"2026-09-04T05:45:06.334128386Z","published":"2026-09-04T05:18:47Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-04T05:39:32.523061256Z","modified_time":"2026-09-04T05:19:05Z","sha256":"989e6d862a8e433df7f0bd31ab9a6b76f616273783517c81f5e428ad2774ad4e","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019474"},{"id":"IN-MAL-2026-019479","import_time":"2026-09-04T05:39:32.892939898Z","modified_time":"2026-09-04T05:19:52Z","sha256":"fdca10627cb3a0de18553a3e5f5e4135126009c9c03cf6a6b866fcbd623a2082","source":"amazon-inspector","versions":["1.0.1"]},{"source":"amazon-inspector","versions":["1.0.3"],"id":"IN-MAL-2026-019475","import_time":"2026-09-04T05:39:32.61796884Z","modified_time":"2026-09-04T05:19:13Z","sha256":"a01e0aa624795d97edc529d9e61f795f990780af533c4ec120b23ba33931134c"},{"import_time":"2026-09-04T05:39:32.369600308Z","modified_time":"2026-09-04T05:18:47Z","sha256":"c1a92d4b0ec61c7a808362033c32297baf3a3783f49ca88ab3d84f3ea9a14b3f","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-019472"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/xcryption/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xcryption/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xcryption/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xcryption/v/1.0.2"}],"affected":[{"package":{"name":"xcryption","ecosystem":"npm","purl":"pkg:npm/xcryption"},"versions":["1.0.0","1.0.1","1.0.3","1.0.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xcryption/MAL-2026-15916.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"bab27aa150c4ae875821d8a813a67b9ebfffb1541744fa0ab5f2aba6b44f91ea","tlsh":"8641a6d916f3523141f3a3d9a7afe41ba18b9613328ed8947d9c91005fa163893a1cdc","path":"scripts/install.js"},{"sha256":"e78751dc7c2c1cb012392730e049d9b920cd7249556a6117a236b6fbd3e2ade9","tlsh":"baf08b208d289e332ac8169559ea0603b1748d0b8804bc1e33d3002c8b9e27f40fe74d","path":"package.json"}],"package_integrity":[{"hashes":{"sha1":"3af96e5acf4e78ab0c3d68ca6cc75115361a6385","sha512_sri":"sha512-FoKQG/Po5nRmYEdKruGwDyl16NIEPiSPVn8FhK5R16wtY4yHsXfsgKvRPAZSqsbKzF+BV7EefTiQo7S/CpMSjg=="},"filename":"xcryption-1.0.0.tgz"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}