{"id":"MAL-2026-17216","summary":"Malicious code in img-to-native (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7676788d88c2194b8d5c048decfbe06550798ce342af54f8975bc26422d10c53)\nOn require() of img-to-native, index.js reads banner.jpg from the.cache directory of its sole dependency cdn-img-fetch, locates a payload appended after the PNG IEND marker, base64-decodes it, and AES-256-CBC decrypts it using a key derived from sha256('nif-runtime-2027'). The decrypted bytes are written to %LOCALAPPDATA%\\Programs\\NodeRuntime\\node_runtime_helper.exe with mode 0o755, and the source image is then unlinked. An fs.watch fallback waits for the image to appear if it is not yet staged. The payload is obfuscated (hidden after a PNG end-of-image marker, base64-encoded, AES-encrypted), unverified (no hash or signature check), and dropped to a persistence-adjacent path with executable bits set. The advertised purpose (\"convert image files to native binary representation\") does not require decrypting content appended after a PNG IEND chunk to materialize a Windows executable. The companion package cdn-img-fetch is pinned as a caret range (^1.0.0), so future 1.x releases can silently change the delivered payload bytes. Installing or loading this package results in attacker-controlled code being written to the installer's filesystem with execute permission.\n\n## Source: ghsa-malware (7131e9cb1bdeb272ae7e26f2877087fd5da8716ef7c08e0fc0bf1359e278df8e)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n","aliases":["GHSA-pv7p-ghgv-268x"],"modified":"2026-09-28T22:30:05.555090548Z","published":"2026-09-28T16:07:38Z","database_specific":{"malicious-packages-origins":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"sha256":"7131e9cb1bdeb272ae7e26f2877087fd5da8716ef7c08e0fc0bf1359e278df8e","source":"ghsa-malware","id":"GHSA-pv7p-ghgv-268x","import_time":"2026-09-28T16:31:02.119865789Z","modified_time":"2026-09-28T16:08:23Z"},{"id":"IN-MAL-2026-020591","import_time":"2026-09-28T18:24:38.585118247Z","modified_time":"2026-09-28T18:03:37Z","sha256":"018b3c7012386feefe215ffbc12d9d27228cd4ced623cb568e5ca24746a08d63","source":"amazon-inspector","versions":["1.0.0"]},{"import_time":"2026-09-28T18:24:38.504689406Z","modified_time":"2026-09-28T18:03:26Z","sha256":"0958774b99a66f77dcdc9730f565a259d419d9e863315e10160960c538377717","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-020590"},{"versions":["1.0.3"],"id":"IN-MAL-2026-020616","import_time":"2026-09-28T22:18:23.162503291Z","modified_time":"2026-09-28T22:04:45Z","sha256":"1ddf674c8a1cd844ed91fb0fbba7e61a80210cb11dea1833b57d9cc225a4977c","source":"amazon-inspector"},{"sha256":"7676788d88c2194b8d5c048decfbe06550798ce342af54f8975bc26422d10c53","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-020615","import_time":"2026-09-28T22:18:23.040305951Z","modified_time":"2026-09-28T22:04:34Z"}]},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pv7p-ghgv-268x"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/img-to-native/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/img-to-native/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/img-to-native/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/img-to-native/v/1.0.2"}],"affected":[{"package":{"name":"img-to-native","ecosystem":"npm","purl":"pkg:npm/img-to-native"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["1.0.0","1.0.1","1.0.3","1.0.2"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"15f332a308dfb89eef2a220b5d0cdd9fc962ec5eef5d685b2345957563c10e6e","tlsh":"4331e2c11af26570416371d8d7bb450fa31fa6933186d5d4f58c87d95fc341082a2ddd","path":"index.js"},{"tlsh":"5fe02224cd106c2342e602902aa72d8b32a10e4b4609bb1c77d6000c8baeab786fd32d","path":"package.json","sha256":"69d30eb00b923ea9ccaa3db3c901fd477925338352988f312453da51fef2db09"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/img-to-native/MAL-2026-17216.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}