-= Per source details. Do not edit below this line.=-
index.js contains a self-invoking IIFE that, 37 seconds after the module is required, reads a base64 blob from test/fixtures/keypairs.dat (a ~53KB opaque file masquerading as test data), decodes it to ~40KB of JavaScript, writes the result to ~/.cache-db/.node-sync/syncd.js with mode 0o700, and spawns it via a detached node child process. Persistence is installed alongside the drop: on Linux a crontab entry is appended running the dropped script every 12 hours, and on Windows a scheduled task named 'WinNodeSync' is created to run it hourly (mod 12). The hidden dot-directory name and the scheduled-task name masquerade as benign Node caching. The package is advertised as a crypto address validator; decoding a bundled opaque blob, writing it to a hidden home-directory path, installing cron/schtasks persistence, and background-executing it has no relationship to that purpose.
{
"malicious-packages-origins": [
{
"import_time": "2026-07-14T14:37:52.102330701Z",
"sha256": "f3d8b69cab723043b20a628a6cd17f0e5cc64051004d9beb43d4b9ed58dbd9a0",
"modified_time": "2026-07-14T13:58:43Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-010511",
"versions": [
"1.0.1"
]
},
{
"import_time": "2026-07-14T18:28:26.820988074Z",
"sha256": "3a4fed71b7064a35b0947a69b3956ad0458fc1440bbd5af37b1eb5c8fc27b64a",
"modified_time": "2026-07-14T17:54:32Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-010534",
"versions": [
"1.0.2"
]
},
{
"import_time": "2026-07-14T18:28:27.124170145Z",
"sha256": "579c4a08980a1a5f07457ba926ae3f15350adc6ed5ba6dc4bc8c5f3388766d22",
"modified_time": "2026-07-14T17:54:47Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-010536",
"versions": [
"1.0.3"
]
},
{
"import_time": "2026-08-19T04:18:13.818458305Z",
"sha256": "ac365c1e0351e0ae05d6a06baee01d3d65f1c325ea0cda8af2a950546ccf0ccc",
"modified_time": "2026-08-19T04:02:08Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018349",
"versions": [
"1.0.0"
]
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/crypto-validate-lib/MAL-2026-10586.json"
{
"evidence_files": [
{
"sha256": "9571dff0efc7bc24e335a031e90250e1816f70de5f7e3d10ca02057afad6f7d8",
"path": "index.js",
"tlsh": "42514245e5f6b2820e71f4b89e7b29337de805e29018da7879ddd0e08f850349479bed"
}
],
"package_integrity": [
{
"filename": "crypto-validate-lib-1.0.1.tgz",
"hashes": {
"sha1": "2f4051def22d5d1d6347a127ecaefc2bb776c926",
"sha512_sri": "sha512-cZYNXJALTlkfaYlI5Cdagj3JOZoVNzvHIFdPS/iDZrLIUiUnI0E0l/uTs0Sus3oMJnnQLcKE+ygLBmlPr0ozPg=="
}
}
]
}
[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]