-= Per source details. Do not edit below this line.=-
package.json declares a postinstall hook that executes a bundled Windows PE launcher (DakuMangalSingh\DakuMangalSingh.exe) at npm install time. The launcher is a jpackage wrapper that loads an embedded JAR named virus.jar containing classes Main, Executor, BatchExecutor, Fetch, RobotService (java.awt.Robot input synthesis), Screenshort (screen capture), and DeviceId (host fingerprinting) — the shape of a remote-command agent with screen-capture and input-synthesis capability. A bundled replicate.bat installs persistence by creating a shortcut to the dropped executable in %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup so the payload auto-runs at every user logon. A cleanup.bat kills the process and recursively deletes the package folder, providing anti-forensics on the installer's host. Installing the package on Windows results in immediate arbitrary code execution, a persistent logon-triggered agent, and evidence-removal tooling — with no legitimate library functionality.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017568",
"import_time": "2026-08-12T12:51:50.851510999Z",
"sha256": "502c2aae77a471762612a5114d299651b7e75571d5c6d9dd5665a3dc2c503327",
"modified_time": "2026-08-12T12:39:55Z",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-017571",
"import_time": "2026-08-12T12:51:51.065941481Z",
"sha256": "89cca10a1d7b205f9caecd1294b9aed12a6eb781599d8b90a854f9fb2c169f2d",
"modified_time": "2026-08-12T12:40:20Z",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-017570",
"import_time": "2026-08-12T12:51:51.017539209Z",
"sha256": "7c6c4376c4b5056a3784ff7a88906659e085c3da56bcd17d445f57e257cbd937",
"versions": [
"1.1.0"
],
"source": "amazon-inspector",
"modified_time": "2026-08-12T12:40:11Z"
},
{
"id": "IN-MAL-2026-017752",
"import_time": "2026-08-14T14:28:05.881686754Z",
"sha256": "948cec286902bdae073ea3a4dbef22a9030ba0ae3003046230445d5c86051c3d",
"versions": [
"2.0.1"
],
"source": "amazon-inspector",
"modified_time": "2026-08-14T14:10:58Z"
},
{
"id": "IN-MAL-2026-017756",
"import_time": "2026-08-14T14:28:06.302812141Z",
"sha256": "a554a197c45fc7c8bd2d2ea4a771a6f1268c35a4c021011ba44e3fc4bcde6e07",
"versions": [
"1.2.0"
],
"source": "amazon-inspector",
"modified_time": "2026-08-14T14:11:33Z"
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dakumangalsingh/MAL-2026-13879.json"
{
"evidence_files": [
{
"path": "package.json",
"tlsh": "dbd0a722884072336870cb540861064677354f1f34344c067fb7154891d36b608d4b06",
"sha256": "0b17ae0e0441639b3029a9cd91b887e4f43b9ff5bb0f8cfec141250e33e68ec7"
},
{
"path": "DakuMangalSingh/app/virus.jar",
"tlsh": "af52bf757dc3a86dfd1bb039c166e0078c2ec1d51e2fb20369aa2c6715b492c871de8d",
"sha256": "8ab43c718b2ac659b35ee28a898601ab7d69ed8c634585538100152fb899e420"
},
{
"path": "replicate.bat",
"tlsh": "9511e131f015e395a2359e4548b85948fa9f44cf1316dc95b809c86daf187cb59fc1c3",
"sha256": "4bae43afe800291e1991cdb81d7945967c372309245f7f69a9a78b7a4284ec06"
},
{
"path": "cleanup.bat",
"tlsh": "5241fd893585762a07738ac09e6010a5fa8c8a6f42752d9d34adc5b02f583c10fff2cd",
"sha256": "cc0381edf2e467687359d1788fac74f46b543859b50130c87d5c7b849d744715"
}
],
"package_integrity": [
{
"filename": "dakumangalsingh-1.0.1.tgz",
"hashes": {
"sha1": "6dfeefa39eb46fbeb62d33f2bdbc69cffc376b60",
"sha512_sri": "sha512-cgiyZ4LaBw3uMuagUQtBFjQbv3NC6apzy643rwgPFPGsvu/s1HQlSXo9UMGQuhkQBKvfnVPMqhkjJcfrPyD+Gg=="
}
}
]
}