MAL-2026-17296

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-agency-assignment-01/MAL-2026-17296.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17296
Published
2026-09-29T23:05:53Z
Modified
2026-09-29T23:30:05Z
Summary
Malicious code in test-agency-assignment-01 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (2098eadf99f0ffe4dc04f478ed085034d30415cb52201be4f36f688298abc46e)

The tarball contains only package.json and an 8.4 MB Go-compiled Windows executable, Kelimasow.exe (sha256 875c7641dc980538f3c3d8b344d173f97cf64a5d97dcf88d8e2932c83b876b92). package.json declares scripts.postinstall = "Kelimasow.exe", so npm install auto-executes this binary on any Windows host. The package has no library code (main points at a nonexistent index.js), no README, no source, no build system, and empty description/author/repository fields, so there is no advertised purpose that would justify shipping an opaque native executable and no way to inspect what the binary does before it runs. Auto-executing a bundled opaque native binary from a package lifecycle hook, with no accompanying source or declared purpose, is the canonical install-time-RCE dropper shape.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020693",
            "import_time":  "2026-09-29T23:17:35.445384579Z",
            "modified_time":  "2026-09-29T23:05:53Z",
            "sha256":  "2098eadf99f0ffe4dc04f478ed085034d30415cb52201be4f36f688298abc46e",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.5"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / test-agency-assignment-01

Package

Name
test-agency-assignment-01
View open source insights on deps.dev
Purl
pkg:npm/test-agency-assignment-01

Affected ranges

Affected versions

1.*
1.0.5

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "77515e56e3703711c39daf49067f3141f00f74ca8ceddb99bacfb931b3bd3e26",
            "tlsh":  "30d0a7234411557325f446640935a51ab512cf1f60b41c0bb1f3191851e3a724898b07"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "test-agency-assignment-01-1.0.5.tgz",
            "hashes":  {
                "sha1":  "21b861376702dd51d6a8db6c8787c1a8aae0641a",
                "sha512_sri":  "sha512-1C322l2snArCescGGHIWJ0SVLPhXxjVfAoP7TeTOa+r9LaSdDdTHegl0XC3rs3Uita3q1PcP8GGMAxr8cmtR7w=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-agency-assignment-01/MAL-2026-17296.json"