MAL-2026-17295

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-agency-assign/MAL-2026-17295.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17295
Published
2026-09-29T23:05:30Z
Modified
2026-09-29T23:30:04Z
Summary
Malicious code in test-agency-assign (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e650e815b4409c3c07cdab7c953ed69b8052f32a28c3686397ab362bb1bd4552)

test-agency-assign@1.0.4 declares a package.json postinstall script wscript.exe Kelimasow.exe that auto-executes a bundled 8.4 MB Go-compiled Windows PE (Kelimasow.exe, sha256 875c7641dc980538f3c3d8b344d173f97cf64a5d97dcf88d8e2932c83b876b92) on npm install. The package has no README, empty description and author fields, no source code, and no other functional content — the manifest is a thin wrapper whose sole install-time effect is to execute an opaque native binary on the installer's machine. Opaque binary + lifecycle-hook auto-execution + missing metadata is the canonical install-time RCE / dropper packaging shape, giving whoever published this arbitrary code execution on any Windows host that installs the package.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020691",
            "import_time":  "2026-09-29T23:17:35.266103243Z",
            "modified_time":  "2026-09-29T23:05:30Z",
            "sha256":  "e650e815b4409c3c07cdab7c953ed69b8052f32a28c3686397ab362bb1bd4552",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.4"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / test-agency-assign

Package

Name
test-agency-assign
View open source insights on deps.dev
Purl
pkg:npm/test-agency-assign

Affected ranges

Affected versions

1.*
1.0.4

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "577410aef0b64584a96e22a53957026db6fd986dce8e35ec41413e61702260f7",
            "tlsh":  "e9d0a7274c55997325f4475459369406f512cf1f50755c4bb1f3641c95e3ab24889b07"
        },
        {
            "path":  "Kelimasow.exe",
            "sha256":  "875c7641dc980538f3c3d8b344d173f97cf64a5d97dcf88d8e2932c83b876b92",
            "tlsh":  "6286f727228414dcc58bc37245f16d7917b33caa1532b79b4ed8bea42f02796af35b48"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "test-agency-assign-1.0.4.tgz",
            "hashes":  {
                "sha1":  "8ca5d37721d6e36333bf0f6ff2867e47a7d88a94",
                "sha512_sri":  "sha512-bor5lCiYmZldV4snptBpNPvRVr2KrEj5YVQWQvjkOdiH8h5vwzGyKpQ8TbBQ/yKBgppT+HYuetWOaeER/ENDhA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-agency-assign/MAL-2026-17295.json"