-= Per source details. Do not edit below this line.=-
The package name suggests a Windows build helper utility, but no concrete behavioral evidence is available to confirm or refute installer-side risk. No exfiltration, install-time fetch, credential access, or other attack-class behavior was observed. The package warrants human review to confirm contents and intent before issuing a public verdict.
{
"malicious-packages-origins": [
{
"id": "RLMA-2026-05653",
"import_time": "2026-07-20T13:14:53.790441043Z",
"modified_time": "2026-07-20T11:04:39Z",
"sha256": "7f6c85194f2cc39ade690b7b9a94332657b6251b638d8908080bedf5b98d908f",
"source": "reversing-labs",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-013032",
"import_time": "2026-08-05T06:00:33.27134744Z",
"modified_time": "2026-08-05T05:24:07Z",
"sha256": "03bd3facc00c36861223058a572fbaa888d815a06c7b309c44639c544c65f1d9",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "RLUA-2026-06552",
"import_time": "2026-09-01T11:38:20.417964332Z",
"modified_time": "2026-08-24T17:17:13Z",
"sha256": "26e3dee77c0d7ff1e6dd5b799e65f48cb574e70615a72d3631410e713de15b7d",
"source": "reversing-labs"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"package_integrity": [
{
"filename": "win-build-utils-1.0.0.tgz",
"hashes": {
"sha1": "eac5474260e937bbccff8bfcbf2575d0d888841c",
"sha512_sri": "sha512-ab4OMCFy4pdz5MC7Ea6aK49RMCSbZTiHuPhE+efmgTeDH5XHA8KDd/JmHfmQDRC3Z2vbEocuIc45BSl6L9CraQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/win-build-utils/MAL-2026-10905.json"