MAL-2026-11542

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/osinthell/MAL-2026-11542.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11542
Published
2026-08-04T22:05:16Z
Modified
2026-08-05T03:20:52.042056959Z
Summary
Malicious code in osinthell (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (458757b4c185e84321b45bd7fec158459300d68106826e5774df2399818c7916)

The package's only exported function, sorgu(), invokes 26 sibling modules under public/a/b/.../z/ that carry out an immediate, irreversible destructive attack on the caller's Windows host. Observed behaviors include: opening \.\PhysicalDrive0 and overwriting the MBR with a zeroed 512-byte buffer (h.js); recursive deletion of C:\ and C:\Windows\System32 (c.js, d.js); running format C: /Q /Y and rd /S /Q C:\ (f.js); taskkill of winlogon/csrss/explorer/dwm (e.js); overwriting C:\Windows\System32\drivers\etc\hosts to blackhole google.com, discord.com, github.com, youtube.com, reddit.com, microsoft.com, and windows.com to 0.0.0.0 (g.js); a self-replicating fork bomb spawning cpus*200 detached node processes plus 1000 cmd loops and 500 powershell infinite loops (i.js); repeated 1GB Buffer allocations in an infinite loop (j.js); unbounded intervals for CPU exhaustion (b.js, y.js); download of a JPEG from https://cdn.discordapp.com/attachments/1525228680803123300/1532140349378531328/photo-output.jpg into %TEMP% and forced fullscreen display via start/mshta/powershell WinForms (a.js); and a forced immediate reboot via shutdown /r /f /t 0 (z.js). The package name and advertised utility purpose are a cover; the exported API is the payload.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-08-04T22:30:11.012763635Z",
            "modified_time": "2026-08-04T22:05:16Z",
            "sha256": "4323c2f3c854c418907138b8caca1e8a74a801cd1108e2d34b4da4f384728174",
            "id": "IN-MAL-2026-011325",
            "versions": [
                "1.9.5"
            ],
            "source": "amazon-inspector"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-04T22:05:42Z",
            "sha256": "4c053414abcdfcca23c4f9d705fe32d7d735389ae13a2d5490da107792b9c18f",
            "id": "IN-MAL-2026-011328",
            "versions": [
                "1.0.1"
            ],
            "import_time": "2026-08-04T22:30:11.145118279Z"
        },
        {
            "import_time": "2026-08-04T22:30:11.103477673Z",
            "modified_time": "2026-08-04T22:05:34Z",
            "sha256": "730baa19026e3249c382e37bac44b63c49d3ba19bf587fbe22fa4ae4118140f4",
            "id": "IN-MAL-2026-011327",
            "versions": [
                "1.6.9"
            ],
            "source": "amazon-inspector"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-04T22:05:49Z",
            "sha256": "839c397fbfc37cc55353b7df0211f5e53ad1445f638cef6e4a7e91bb716b049b",
            "id": "IN-MAL-2026-011329",
            "versions": [
                "1.0.5"
            ],
            "import_time": "2026-08-04T22:30:11.173671383Z"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-04T22:06:07Z",
            "sha256": "458757b4c185e84321b45bd7fec158459300d68106826e5774df2399818c7916",
            "id": "IN-MAL-2026-011331",
            "versions": [
                "1.9.1"
            ],
            "import_time": "2026-08-04T22:30:11.279991159Z"
        },
        {
            "import_time": "2026-08-05T03:11:16.336939362Z",
            "modified_time": "2026-08-05T01:42:52Z",
            "sha256": "c49951bbd2d5903fcfbfd539e209d9e1ecb2ce7d4a654d9a0135b50447b72ce6",
            "id": "IN-MAL-2026-011515",
            "versions": [
                "1.6.6"
            ],
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / osinthell

Package

Affected ranges

Affected versions

1.*
1.0.1
1.0.5
1.6.6
1.6.9
1.9.1
1.9.5

Database specific

cwes
[
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    }
]
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-U/aYCDVY9sh/f3iATst+mq+08aE3spNPeiemK0DswRKhi11ny6ULlLkL5jjvX/UlV8fOLv0/XLz92NDeugnqRQ==",
                "sha1": "c655ca0b11a34ff359aabc2d8819b7c5b6e5475e"
            },
            "filename": "osinthell-1.9.5.tgz"
        }
    ],
    "evidence_files": [
        {
            "path": "index.js",
            "sha256": "496af023249908c73005235c7aa348a1604ec70c6b13b07eb30641908b4a207e",
            "tlsh": "405165119e63f2559d906ed9a338c512f8d7603eb3ce06c3f69937e699540940a01c37"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/osinthell/MAL-2026-11542.json"