MAL-2026-13879

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dakumangalsingh/MAL-2026-13879.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13879
Published
2026-08-12T12:39:55Z
Modified
2026-08-14T14:46:35.906534558Z
Summary
Malicious code in dakumangalsingh (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (502c2aae77a471762612a5114d299651b7e75571d5c6d9dd5665a3dc2c503327)

package.json declares a postinstall hook that executes a bundled Windows PE launcher (DakuMangalSingh\DakuMangalSingh.exe) at npm install time. The launcher is a jpackage wrapper that loads an embedded JAR named virus.jar containing classes Main, Executor, BatchExecutor, Fetch, RobotService (java.awt.Robot input synthesis), Screenshort (screen capture), and DeviceId (host fingerprinting) — the shape of a remote-command agent with screen-capture and input-synthesis capability. A bundled replicate.bat installs persistence by creating a shortcut to the dropped executable in %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup so the payload auto-runs at every user logon. A cleanup.bat kills the process and recursively deletes the package folder, providing anti-forensics on the installer's host. Installing the package on Windows results in immediate arbitrary code execution, a persistent logon-triggered agent, and evidence-removal tooling — with no legitimate library functionality.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-017568",
            "import_time": "2026-08-12T12:51:50.851510999Z",
            "sha256": "502c2aae77a471762612a5114d299651b7e75571d5c6d9dd5665a3dc2c503327",
            "modified_time": "2026-08-12T12:39:55Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-017571",
            "import_time": "2026-08-12T12:51:51.065941481Z",
            "sha256": "89cca10a1d7b205f9caecd1294b9aed12a6eb781599d8b90a854f9fb2c169f2d",
            "modified_time": "2026-08-12T12:40:20Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-017570",
            "import_time": "2026-08-12T12:51:51.017539209Z",
            "sha256": "7c6c4376c4b5056a3784ff7a88906659e085c3da56bcd17d445f57e257cbd937",
            "versions": [
                "1.1.0"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-12T12:40:11Z"
        },
        {
            "id": "IN-MAL-2026-017752",
            "import_time": "2026-08-14T14:28:05.881686754Z",
            "sha256": "948cec286902bdae073ea3a4dbef22a9030ba0ae3003046230445d5c86051c3d",
            "versions": [
                "2.0.1"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-14T14:10:58Z"
        },
        {
            "id": "IN-MAL-2026-017756",
            "import_time": "2026-08-14T14:28:06.302812141Z",
            "sha256": "a554a197c45fc7c8bd2d2ea4a771a6f1268c35a4c021011ba44e3fc4bcde6e07",
            "versions": [
                "1.2.0"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-14T14:11:33Z"
        }
    ]
}
References
Credits

Affected packages

npm / dakumangalsingh

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.1.0
1.2.0
2.*
2.0.1

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dakumangalsingh/MAL-2026-13879.json"
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "tlsh": "dbd0a722884072336870cb540861064677354f1f34344c067fb7154891d36b608d4b06",
            "sha256": "0b17ae0e0441639b3029a9cd91b887e4f43b9ff5bb0f8cfec141250e33e68ec7"
        },
        {
            "path": "DakuMangalSingh/app/virus.jar",
            "tlsh": "af52bf757dc3a86dfd1bb039c166e0078c2ec1d51e2fb20369aa2c6715b492c871de8d",
            "sha256": "8ab43c718b2ac659b35ee28a898601ab7d69ed8c634585538100152fb899e420"
        },
        {
            "path": "replicate.bat",
            "tlsh": "9511e131f015e395a2359e4548b85948fa9f44cf1316dc95b809c86daf187cb59fc1c3",
            "sha256": "4bae43afe800291e1991cdb81d7945967c372309245f7f69a9a78b7a4284ec06"
        },
        {
            "path": "cleanup.bat",
            "tlsh": "5241fd893585762a07738ac09e6010a5fa8c8a6f42752d9d34adc5b02f583c10fff2cd",
            "sha256": "cc0381edf2e467687359d1788fac74f46b543859b50130c87d5c7b849d744715"
        }
    ],
    "package_integrity": [
        {
            "filename": "dakumangalsingh-1.0.1.tgz",
            "hashes": {
                "sha1": "6dfeefa39eb46fbeb62d33f2bdbc69cffc376b60",
                "sha512_sri": "sha512-cgiyZ4LaBw3uMuagUQtBFjQbv3NC6apzy643rwgPFPGsvu/s1HQlSXo9UMGQuhkQBKvfnVPMqhkjJcfrPyD+Gg=="
            }
        }
    ]
}