MAL-2026-17299

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/testosu8887/MAL-2026-17299.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17299
Published
2026-09-29T23:05:23Z
Modified
2026-09-29T23:30:05Z
Summary
Malicious code in testosu8887 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (7d9d3296b770afd3fdebaf4df9d113873e9c77d2d498d2e7941a3465eeb6f97d)

On require or CLI invocation, dist/index.cjs and dist/cli.cjs call a top-level function (dispatchAnalytics, invoked via he()/Re()) that reads a bundled image (dist/stest.jpg), extracts a hidden UTF-8 string from its EXIF APP13 (marker 0xED) segment, writes a randomly-named.vbs file to the OS temp directory, and spawns wscript.exe detached with windowsHide:true to run it. The VBS launches powershell.exe with an -EncodedCommand argument sourced from the image; the decoded PowerShell downloads https://m1.ppy.sh/r/osu!install.exe to %LOCALAPPDATA%\Temp\lahost.exe and executes it via Start-Process. Sensitive tokens are assembled at runtime from array joins (["power","shell",".exe"].join(""), ["wscript",".exe"].join(""), split -NoProfile/-NonInteractive/-EncodedCommand fragments) and the payload body is hidden in JPEG EXIF rather than present as source strings, concealing the behavior from static scanners. The package name suggests a test/typosquat targeting the osu! game community.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020690",
            "import_time":  "2026-09-29T23:17:35.110432381Z",
            "modified_time":  "2026-09-29T23:05:23Z",
            "sha256":  "7d9d3296b770afd3fdebaf4df9d113873e9c77d2d498d2e7941a3465eeb6f97d",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / testosu8887

Package

Affected ranges

Affected versions

1.*
1.0.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "dist/index.cjs",
            "sha256":  "97fa0d7666e80c68a3cd4f3326dc31bd9203619d6bbae7449efe62de15c4e815",
            "tlsh":  "4262f784b3dcb03617eb62e190ab4407e9f5da95408c1418f294e4bb35e46db42fbf79"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "testosu8887-1.0.1.tgz",
            "hashes":  {
                "sha1":  "5bfcaae8723847baf2898c1b3e1d924ab68edf7c",
                "sha512_sri":  "sha512-2uLHmNF2WteyqIp5aRnh/WhfpRd14pGvf+yIgFMd2w7M8y00wZ+EwS9F2T4oegBRZs6TSf/oE8O9FIZtz0ornQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/testosu8887/MAL-2026-17299.json"