{"id":"MAL-2026-16363","summary":"Malicious code in blue-string-formatter-utilss (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (de9e55c734c18f91b4b3a043dd6539097aa4e57056ff9dca6df1a9d3a3631c25)\nThe package advertises itself as string-formatting utilities but ships no formatter code. Its main entry `payload.js` is an IIFE that creates a `\u003cscript\u003e` element with `src='https://xss.report/c/k3rne111'` and appends it to `document.body`, causing an attacker-controlled remote script to be fetched and executed whenever the module is loaded in a DOM context. xss.report is a known XSS payload-delivery service. The name-versus-behavior mismatch (a 'string formatter' whose only behavior is a remote script loader) is a typosquat cover story rather than legitimate functionality.\n","modified":"2026-09-21T20:30:13.916088941Z","published":"2026-09-21T19:48:44Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-21T19:48:44Z","sha256":"de9e55c734c18f91b4b3a043dd6539097aa4e57056ff9dca6df1a9d3a3631c25","source":"amazon-inspector","versions":["1.2.0"],"id":"IN-MAL-2026-020274","import_time":"2026-09-21T20:17:15.574332821Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/blue-string-formatter-utilss/v/1.2.0"}],"affected":[{"package":{"name":"blue-string-formatter-utilss","ecosystem":"npm","purl":"pkg:npm/blue-string-formatter-utilss"},"versions":["1.2.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"blue-string-formatter-utilss-1.2.0.tgz","hashes":{"sha1":"4951b006f430783f4212c71b82ed526634c7fcec","sha512_sri":"sha512-9e1vDf8tc84riO32Kn4FL3tSzj4tcfa0wKZNfbxZnu4Ag9+RHDsBfBYF14mFjrvjT4belIJADXnIrxb8filtnQ=="}}],"evidence_files":[{"path":"payload.js","sha256":"27d2c92ea7e1674ad1185b4c4c157beb7a6d2a973bf493f2d832dc9775e79b3b","tlsh":"85c08c2e1da8d02000322adb2137ea58367118282812e10564e8d91ca820fd60c06cd4"},{"path":"package.json","sha256":"713bb0976664c7154ec320b6401f48f19819188eaecc11b749cc83f39caeab5f","tlsh":"cbd02b20ca52443319c1411f5c94d142a338ef0f14403c1e9bdf250c434daf6a9f678d"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/blue-string-formatter-utilss/MAL-2026-16363.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}