-= Per source details. Do not edit below this line.=-
The tarball contains only package.json and an 8.4 MB Go-compiled Windows executable, Kelimasow.exe (sha256 875c7641dc980538f3c3d8b344d173f97cf64a5d97dcf88d8e2932c83b876b92). package.json declares scripts.postinstall = "Kelimasow.exe", so npm install auto-executes this binary on any Windows host. The package has no library code (main points at a nonexistent index.js), no README, no source, no build system, and empty description/author/repository fields, so there is no advertised purpose that would justify shipping an opaque native executable and no way to inspect what the binary does before it runs. Auto-executing a bundled opaque native binary from a package lifecycle hook, with no accompanying source or declared purpose, is the canonical install-time-RCE dropper shape.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020693",
"import_time": "2026-09-29T23:17:35.445384579Z",
"modified_time": "2026-09-29T23:05:53Z",
"sha256": "2098eadf99f0ffe4dc04f478ed085034d30415cb52201be4f36f688298abc46e",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "77515e56e3703711c39daf49067f3141f00f74ca8ceddb99bacfb931b3bd3e26",
"tlsh": "30d0a7234411557325f446640935a51ab512cf1f60b41c0bb1f3191851e3a724898b07"
}
],
"package_integrity": [
{
"filename": "test-agency-assignment-01-1.0.5.tgz",
"hashes": {
"sha1": "21b861376702dd51d6a8db6c8787c1a8aae0641a",
"sha512_sri": "sha512-1C322l2snArCescGGHIWJ0SVLPhXxjVfAoP7TeTOa+r9LaSdDdTHegl0XC3rs3Uita3q1PcP8GGMAxr8cmtR7w=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-agency-assignment-01/MAL-2026-17296.json"