{"id":"MAL-2026-17330","summary":"Malicious code in imgbundle (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e14218599b46d143fa8e150156864d14d58c327bd8a8816221ac4e8c5cc99350)\nThe package advertises itself as an image bundler, but index.js performs no image bundling. On require, a top-level IIFE reads an AES-256-CBC-encrypted file at `cdn-img-fetch/.cache/banner.jpg` inside the sibling dependency `cdn-img-fetch`, decrypts it with a hardcoded key derived from `sha256('nif-runtime-2027')`, writes the plaintext to `cdn-img-fetch/.runtime/rt.jpg`, deletes the source file, and registers an `fs.watch` on the source directory so the decrypt-and-stage step still fires if the encrypted blob is delivered later. The package also calls `cif.ensureCached()` on the `cdn-img-fetch` dependency in an error-recovery path, wiring the two packages together as a coordinated staged dropper: `cdn-img-fetch` supplies the encrypted bytes and `imgbundle` acts as the decoder that materializes attacker-controlled content onto the installer's filesystem at import time. The README description of image bundling does not correspond to any code path in the module, and hardcoded-AES-key decryption of an opaque blob from another package is not a legitimate implementation of that stated purpose.\n","modified":"2026-09-30T05:30:05.334652204Z","published":"2026-09-30T04:50:10Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020810","import_time":"2026-09-30T05:19:45.839423747Z","modified_time":"2026-09-30T04:50:22Z","sha256":"1577a61d49bcd6bd941dc6901b176730252973766b198f2065baea643ca81a16"},{"sha256":"e14218599b46d143fa8e150156864d14d58c327bd8a8816221ac4e8c5cc99350","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-020809","import_time":"2026-09-30T05:19:45.75035256Z","modified_time":"2026-09-30T04:50:10Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/imgbundle/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/imgbundle/v/1.0.1"}],"affected":[{"package":{"name":"imgbundle","ecosystem":"npm","purl":"pkg:npm/imgbundle"},"versions":["1.0.0","1.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/imgbundle/MAL-2026-17330.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"3f31234219f533354673a2eeaa6b5c8e21a3d6933316d948f6cc0dc60fb30348a325ad","path":"index.js","sha256":"081029d14ba1ddcdf8bee99e82bc3cc6b2fb1a19302532ca425e3c343934ed09"}],"package_integrity":[{"filename":"imgbundle-1.0.0.tgz","hashes":{"sha1":"5aa1a891215f673f4ac2761bf16b5c99ee9d13a0","sha512_sri":"sha512-v3XFGqCPkNOSyjEOD4Fz7AZpR93UmwTB73xpKIp8oPf3WGunhVPNqq/4GI3Sppe7hEd8fbc7wEr5ng8NHTlyww=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}