-= Per source details. Do not edit below this line.=-
On require or CLI invocation, dist/index.cjs and dist/cli.cjs call a top-level function (dispatchAnalytics, invoked via he()/Re()) that reads a bundled image (dist/stest.jpg), extracts a hidden UTF-8 string from its EXIF APP13 (marker 0xED) segment, writes a randomly-named.vbs file to the OS temp directory, and spawns wscript.exe detached with windowsHide:true to run it. The VBS launches powershell.exe with an -EncodedCommand argument sourced from the image; the decoded PowerShell downloads https://m1.ppy.sh/r/osu!install.exe to %LOCALAPPDATA%\Temp\lahost.exe and executes it via Start-Process. Sensitive tokens are assembled at runtime from array joins (["power","shell",".exe"].join(""), ["wscript",".exe"].join(""), split -NoProfile/-NonInteractive/-EncodedCommand fragments) and the payload body is hidden in JPEG EXIF rather than present as source strings, concealing the behavior from static scanners. The package name suggests a test/typosquat targeting the osu! game community.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020690",
"import_time": "2026-09-29T23:17:35.110432381Z",
"modified_time": "2026-09-29T23:05:23Z",
"sha256": "7d9d3296b770afd3fdebaf4df9d113873e9c77d2d498d2e7941a3465eeb6f97d",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "dist/index.cjs",
"sha256": "97fa0d7666e80c68a3cd4f3326dc31bd9203619d6bbae7449efe62de15c4e815",
"tlsh": "4262f784b3dcb03617eb62e190ab4407e9f5da95408c1418f294e4bb35e46db42fbf79"
}
],
"package_integrity": [
{
"filename": "testosu8887-1.0.1.tgz",
"hashes": {
"sha1": "5bfcaae8723847baf2898c1b3e1d924ab68edf7c",
"sha512_sri": "sha512-2uLHmNF2WteyqIp5aRnh/WhfpRd14pGvf+yIgFMd2w7M8y00wZ+EwS9F2T4oegBRZs6TSf/oE8O9FIZtz0ornQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/testosu8887/MAL-2026-17299.json"