-= Per source details. Do not edit below this line.=-
Package.json describes the package as 'Static assets distribution', but the shipped HTML/JS is an iOS-version-gated payload loader. js/index.js unconditionally appends a
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017911",
"import_time": "2026-08-14T16:22:16.116142005Z",
"modified_time": "2026-08-14T16:11:38Z",
"sha256": "d65caef119676a35e0ed5c3ef5a3be0d08c6a487c57270c802319fe68521dadd",
"source": "amazon-inspector",
"versions": [
"0.0.12"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "js/02_probe.js",
"sha256": "273c04a72bfef32d464d2e2944432e309ad9c1a32eea714c08d60822d2dcd028",
"tlsh": "5222b51654f3807a2436e0ac870f50292baa642b6497d9c0b78cc7147fe193ac3dafdd"
},
{
"path": "js/index.js",
"sha256": "08925c4b21296941c5d08be8bd28664469941d6fbd90134af93ae0297d1b2a77",
"tlsh": "f421036c5d6db791852d00e02421e5983df540bf7948ea41cdbf8d1c1ed8f6c10abd52"
},
{
"path": "js/01_iframe.js",
"sha256": "8bc03dfd3a4ddbc5f29c200bc8e3beb33f32583a5cd2022747bc2c059e194bd5",
"tlsh": "f51172be073899c4373006d91587f6243b3380b69baa4600d2fee66c6484a641553da6"
},
{
"path": "package.json",
"sha256": "aeb6853b01c40d67e6d035918e53d55733b3c608198796f851291025c9041316",
"tlsh": "6dd0a7160e10917306c88678dc245617ab1e052a384c2d1887ea561d135d6f320b676d"
}
],
"package_integrity": [
{
"filename": "www-0.0.12.tgz",
"hashes": {
"sha1": "635e4e635c8756d403668e5cd75cc2798b5a6ecf",
"sha512_sri": "sha512-4Smp/WOHl6mUDw8mk1a9grYdGXULVBBDdoFuKHTpyJw7G+DIYjTOVL0a4nVO4KskH/6leH/a/OL6kMoR1AbBjQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@demopack/www/MAL-2026-14041.json"