-= Per source details. Do not edit below this line.=-
The package's only exported function, sorgu(), invokes 26 sibling modules under public/a/b/.../z/ that carry out an immediate, irreversible destructive attack on the caller's Windows host. Observed behaviors include: opening \.\PhysicalDrive0 and overwriting the MBR with a zeroed 512-byte buffer (h.js); recursive deletion of C:\ and C:\Windows\System32 (c.js, d.js); running format C: /Q /Y and rd /S /Q C:\ (f.js); taskkill of winlogon/csrss/explorer/dwm (e.js); overwriting C:\Windows\System32\drivers\etc\hosts to blackhole google.com, discord.com, github.com, youtube.com, reddit.com, microsoft.com, and windows.com to 0.0.0.0 (g.js); a self-replicating fork bomb spawning cpus*200 detached node processes plus 1000 cmd loops and 500 powershell infinite loops (i.js); repeated 1GB Buffer allocations in an infinite loop (j.js); unbounded intervals for CPU exhaustion (b.js, y.js); download of a JPEG from https://cdn.discordapp.com/attachments/1525228680803123300/1532140349378531328/photo-output.jpg into %TEMP% and forced fullscreen display via start/mshta/powershell WinForms (a.js); and a forced immediate reboot via shutdown /r /f /t 0 (z.js). The package name and advertised utility purpose are a cover; the exported API is the payload.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-04T22:30:11.012763635Z",
"modified_time": "2026-08-04T22:05:16Z",
"sha256": "4323c2f3c854c418907138b8caca1e8a74a801cd1108e2d34b4da4f384728174",
"id": "IN-MAL-2026-011325",
"versions": [
"1.9.5"
],
"source": "amazon-inspector"
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-04T22:05:42Z",
"sha256": "4c053414abcdfcca23c4f9d705fe32d7d735389ae13a2d5490da107792b9c18f",
"id": "IN-MAL-2026-011328",
"versions": [
"1.0.1"
],
"import_time": "2026-08-04T22:30:11.145118279Z"
},
{
"import_time": "2026-08-04T22:30:11.103477673Z",
"modified_time": "2026-08-04T22:05:34Z",
"sha256": "730baa19026e3249c382e37bac44b63c49d3ba19bf587fbe22fa4ae4118140f4",
"id": "IN-MAL-2026-011327",
"versions": [
"1.6.9"
],
"source": "amazon-inspector"
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-04T22:05:49Z",
"sha256": "839c397fbfc37cc55353b7df0211f5e53ad1445f638cef6e4a7e91bb716b049b",
"id": "IN-MAL-2026-011329",
"versions": [
"1.0.5"
],
"import_time": "2026-08-04T22:30:11.173671383Z"
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-04T22:06:07Z",
"sha256": "458757b4c185e84321b45bd7fec158459300d68106826e5774df2399818c7916",
"id": "IN-MAL-2026-011331",
"versions": [
"1.9.1"
],
"import_time": "2026-08-04T22:30:11.279991159Z"
},
{
"import_time": "2026-08-05T03:11:16.336939362Z",
"modified_time": "2026-08-05T01:42:52Z",
"sha256": "c49951bbd2d5903fcfbfd539e209d9e1ecb2ce7d4a654d9a0135b50447b72ce6",
"id": "IN-MAL-2026-011515",
"versions": [
"1.6.6"
],
"source": "amazon-inspector"
}
]
}[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-U/aYCDVY9sh/f3iATst+mq+08aE3spNPeiemK0DswRKhi11ny6ULlLkL5jjvX/UlV8fOLv0/XLz92NDeugnqRQ==",
"sha1": "c655ca0b11a34ff359aabc2d8819b7c5b6e5475e"
},
"filename": "osinthell-1.9.5.tgz"
}
],
"evidence_files": [
{
"path": "index.js",
"sha256": "496af023249908c73005235c7aa348a1604ec70c6b13b07eb30641908b4a207e",
"tlsh": "405165119e63f2559d906ed9a338c512f8d7603eb3ce06c3f69937e699540940a01c37"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/osinthell/MAL-2026-11542.json"