{"id":"MAL-2026-17299","summary":"Malicious code in testosu8887 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7d9d3296b770afd3fdebaf4df9d113873e9c77d2d498d2e7941a3465eeb6f97d)\nOn require or CLI invocation, dist/index.cjs and dist/cli.cjs call a top-level function (`dispatchAnalytics`, invoked via `he()`/`Re()`) that reads a bundled image (dist/stest.jpg), extracts a hidden UTF-8 string from its EXIF APP13 (marker 0xED) segment, writes a randomly-named.vbs file to the OS temp directory, and spawns wscript.exe detached with `windowsHide:true` to run it. The VBS launches powershell.exe with an `-EncodedCommand` argument sourced from the image; the decoded PowerShell downloads https://m1.ppy.sh/r/osu!install.exe to %LOCALAPPDATA%\\Temp\\lahost.exe and executes it via Start-Process. Sensitive tokens are assembled at runtime from array joins (`[\"power\",\"shell\",\".exe\"].join(\"\")`, `[\"wscript\",\".exe\"].join(\"\")`, split `-NoProfile`/`-NonInteractive`/`-EncodedCommand` fragments) and the payload body is hidden in JPEG EXIF rather than present as source strings, concealing the behavior from static scanners. The package name suggests a test/typosquat targeting the osu! game community.\n","modified":"2026-09-29T23:30:05.068150993Z","published":"2026-09-29T23:05:23Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-020690","import_time":"2026-09-29T23:17:35.110432381Z","modified_time":"2026-09-29T23:05:23Z","sha256":"7d9d3296b770afd3fdebaf4df9d113873e9c77d2d498d2e7941a3465eeb6f97d","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/testosu8887/v/1.0.1"}],"affected":[{"package":{"name":"testosu8887","ecosystem":"npm","purl":"pkg:npm/testosu8887"},"versions":["1.0.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"dist/index.cjs","sha256":"97fa0d7666e80c68a3cd4f3326dc31bd9203619d6bbae7449efe62de15c4e815","tlsh":"4262f784b3dcb03617eb62e190ab4407e9f5da95408c1418f294e4bb35e46db42fbf79"}],"package_integrity":[{"filename":"testosu8887-1.0.1.tgz","hashes":{"sha512_sri":"sha512-2uLHmNF2WteyqIp5aRnh/WhfpRd14pGvf+yIgFMd2w7M8y00wZ+EwS9F2T4oegBRZs6TSf/oE8O9FIZtz0ornQ==","sha1":"5bfcaae8723847baf2898c1b3e1d924ab68edf7c"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/testosu8887/MAL-2026-17299.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}