-= Per source details. Do not edit below this line.=-
dist/index.js appends a heavily obfuscated obfuscator.io-style payload (string array _0x240a of length 303, decoder _0x4963, string-array rotation) after the clean TypeScript-compiled validation code. None of this obfuscated code is declared in dist/index.d.ts and it executes at top level on import '@wizloft/harness-validation'. Decoded string fragments include Ethereum RPC / block-explorer hostnames (h.drpc.org, pc.io/eth, stapi.io), a hardcoded attacker Ethereum address (0xa322E5f3...), Etherscan-style query parameters (?module=account, filterby=from), a spoofed browser User-Agent, and application/json / content-encoding request framing. The payload queries the block explorer for transactions from the hardcoded wallet, extracts a URL/payload from the transaction data, then fetches and executes the resolved content — a blockchain-based dead-drop that lets the publisher rotate the delivered code by posting a new transaction from that wallet, giving them a persistent mutable remote-code channel against every process that imports the library. Sibling packages in the @wizloft/* namespace (@wizloft/harness-evidence, @wizloft/harness-kernel) are declared dependencies at matching alpha versions and exhibit the same trojanized-library shape.
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-018410",
"import_time": "2026-08-19T08:48:53.767355574Z",
"modified_time": "2026-08-19T08:33:31Z",
"sha256": "67b0fc0f25eb3d7852b52d7e7db50071ac08ddfb1965df306bbf87ebf295cbe1",
"source": "amazon-inspector",
"versions": [
"0.1.1-alpha.3"
]
},
{
"id": "GHSA-7g98-grc6-6xjh",
"import_time": "2026-09-23T00:57:12.942288688Z",
"modified_time": "2026-09-23T00:24:46Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "08e84866a8eb31e1d31d47bfec773dde1fa378080daf7998a189075bc5eda666",
"source": "ghsa-malware"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "dist/index.js",
"sha256": "affc08739ab30ac2c3d610cbee1e116fce4bc45c6fb88a5c4e62ecf42e107edc",
"tlsh": "fe23b7c47bd0644003476abb6b0bf0e1f97a18ae75884986f21cfa90ef5632bd5f1635"
}
],
"package_integrity": [
{
"filename": "harness-validation-0.1.1-alpha.3.tgz",
"hashes": {
"sha1": "540d7396e8a00dce871668bb46ce790480f4a2cc",
"sha512_sri": "sha512-L4En6T5cJ6xNU7vQgabDEJBYhy8JbxW/x0/Bpe4zZDFyMWHqjWbSrDsdpJCIHDZbPEmE2yJNnmXeK/LSj4LR+A=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wizloft/harness-validation/MAL-2026-14289.json"