{"id":"MAL-2026-16053","summary":"Malicious code in file-type-detector (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (04917bd7fc156dcb9793cb1f1d06ed0f2d0cb1b3aa4b04431dea54ed71f6be72)\nA clone of file-type-checker with one function added: isSign(name, moduleName, offset) in dist/validation/image.js reads public/${name}.png from the working directory, splits the buffer at -offset, and writes the trailing payload to../../../{moduleName}/log - a sibling package under node_modules - then returns isPNG() so the caller sees a plausible boolean. It is undocumented, reachable only via an __exportStar wildcard so it is never named in dist/index.js, and fails silently on try/catch.\n\nDrop stage of a three-package chain: file-type-detector writes the payload, gloggo (1.1.2-1.1.4) executes it via require('./log'), and sonmors (typosquat of sonner) triggers the chain by requiring gloggo. gloggo shares the npm publisher log-developer and was published five minutes apart on 2026-08-27. No install hooks; execution occurs on require().\n","modified":"2026-09-09T01:00:05.002081678Z","published":"2026-09-09T00:27:12Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-019729","import_time":"2026-09-09T00:47:58.112210798Z","modified_time":"2026-09-09T00:27:12Z","sha256":"04917bd7fc156dcb9793cb1f1d06ed0f2d0cb1b3aa4b04431dea54ed71f6be72","source":"amazon-inspector","versions":["1.1.0"]},{"sha256":"71bc73a30f67553cd6a23058191a0e93333a056cbcb85896fbfc87b2e3a4e477","source":"amazon-inspector","versions":["1.1.1"],"id":"IN-MAL-2026-019730","import_time":"2026-09-09T00:47:58.190429304Z","modified_time":"2026-09-09T00:27:22Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/file-type-detector/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/file-type-detector/v/1.1.1"}],"affected":[{"package":{"name":"file-type-detector","ecosystem":"npm","purl":"pkg:npm/file-type-detector"},"versions":["1.1.0","1.1.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/file-type-detector/MAL-2026-16053.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"c3452c877f280788620ba728592d5dac71c2958d","sha512_sri":"sha512-xrefg9CLEpfg+lb5YVdyFHlsV/ZF8Xrt+MsYSAkj38bJmbZ28a3ZgBP0ETKAIs6AQOMgqGp2WHIPpwhLGjapAw=="},"filename":"file-type-detector-1.1.0.tgz"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}