-= Per source details. Do not edit below this line.=-
test-agency-assign@1.0.4 declares a package.json postinstall script wscript.exe Kelimasow.exe that auto-executes a bundled 8.4 MB Go-compiled Windows PE (Kelimasow.exe, sha256 875c7641dc980538f3c3d8b344d173f97cf64a5d97dcf88d8e2932c83b876b92) on npm install. The package has no README, empty description and author fields, no source code, and no other functional content — the manifest is a thin wrapper whose sole install-time effect is to execute an opaque native binary on the installer's machine. Opaque binary + lifecycle-hook auto-execution + missing metadata is the canonical install-time RCE / dropper packaging shape, giving whoever published this arbitrary code execution on any Windows host that installs the package.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020691",
"import_time": "2026-09-29T23:17:35.266103243Z",
"modified_time": "2026-09-29T23:05:30Z",
"sha256": "e650e815b4409c3c07cdab7c953ed69b8052f32a28c3686397ab362bb1bd4552",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "577410aef0b64584a96e22a53957026db6fd986dce8e35ec41413e61702260f7",
"tlsh": "e9d0a7274c55997325f4475459369406f512cf1f50755c4bb1f3641c95e3ab24889b07"
},
{
"path": "Kelimasow.exe",
"sha256": "875c7641dc980538f3c3d8b344d173f97cf64a5d97dcf88d8e2932c83b876b92",
"tlsh": "6286f727228414dcc58bc37245f16d7917b33caa1532b79b4ed8bea42f02796af35b48"
}
],
"package_integrity": [
{
"filename": "test-agency-assign-1.0.4.tgz",
"hashes": {
"sha1": "8ca5d37721d6e36333bf0f6ff2867e47a7d88a94",
"sha512_sri": "sha512-bor5lCiYmZldV4snptBpNPvRVr2KrEj5YVQWQvjkOdiH8h5vwzGyKpQ8TbBQ/yKBgppT+HYuetWOaeER/ENDhA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-agency-assign/MAL-2026-17295.json"