MAL-2026-5896

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/jest-test-plugin-utils/MAL-2026-5896.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5896
Aliases
  • GHSA-7969-jc8h-fp32
Published
2026-06-16T15:37:20Z
Modified
2026-08-20T22:01:46Z
Summary
Malicious code in jest-test-plugin-utils (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (3f948eff13632557a65152c587b6aa87783e49cf40504aedca8ee15da6ed205e)

The package advertises itself as a Jest plugin (name: 'jest-test-plugin-utils', description: 'mqtt utils') but ships no Jest or MQTT functionality. Its main entry dist/index.js is a heavily obfuscated 200KB browserify bundle (obfuscator.io fingerprint: 1299-entry rotated string array, decoder wrapper, control-flow flattening; built with the declared devDependency 'gulp-javascript-obfuscator'). After deobfuscation, the only meaningful behavior is a function loadFilbetScriptSilently() (exposed as window.fetchFilbetScript) that creates a

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-006765",
            "import_time": "2026-06-16T16:06:34.427097256Z",
            "modified_time": "2026-06-16T15:37:24Z",
            "sha256": "3f948eff13632557a65152c587b6aa87783e49cf40504aedca8ee15da6ed205e",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-006764",
            "import_time": "2026-06-16T16:06:34.332185997Z",
            "modified_time": "2026-06-16T15:37:23Z",
            "sha256": "54c5196f3361da72dfccd2c8abb0caba132415f9907602c5a6ec92d6da2e077f",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-006766",
            "import_time": "2026-06-16T16:06:34.568829617Z",
            "modified_time": "2026-06-16T15:37:30Z",
            "sha256": "bb80fa98045e0dd75514425f419aa986e7e57bfa888d8baaa8c5eb0016418f83",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-006763",
            "import_time": "2026-06-16T16:06:34.127682958Z",
            "modified_time": "2026-06-16T15:37:20Z",
            "sha256": "f5445eba984ab32829120583a68c6bfc2fa8aec2f875b506c873de598f1d27d1",
            "source": "amazon-inspector",
            "versions": [
                "1.0.4"
            ]
        },
        {
            "id": "GHSA-7969-jc8h-fp32",
            "import_time": "2026-08-20T13:33:26.043107536Z",
            "modified_time": "2026-08-20T13:05:33Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "SEMVER"
                }
            ],
            "sha256": "951d82ab1573c962c8c548477013f418229d33a24e4e6a89e509ca4fdb149106",
            "source": "ghsa-malware"
        },
        {
            "id": "IN-MAL-2026-018464",
            "import_time": "2026-08-20T21:43:25.339148887Z",
            "modified_time": "2026-08-20T21:14:38Z",
            "sha256": "149fc5043ae3e73f200138c8c6c88106df7b187c2e08d6ad0dc7e889721de28b",
            "source": "amazon-inspector",
            "versions": [
                "1.0.3"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / jest-test-plugin-utils

Package

Name
jest-test-plugin-utils
View open source insights on deps.dev
Purl
pkg:npm/jest-test-plugin-utils

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "dist/index.js",
            "sha256": "a61584375c14c072e01ec862ed28d36ff0157245a5b195229da9dafa8946a040",
            "tlsh": "e514404077c0b844538b1fba766fb4e5e46b1de934c4090bc515fca0f5baa26fae2934"
        },
        {
            "path": "package.json",
            "sha256": "b152b66b1f3a7e2634d7dcdb3cf45409e2fa55d9770b061f6f6f5c92db06f513",
            "tlsh": "fdf02734dd71987306e820e51c682167e0709d2bc245fd1c33c7140c4a5f2eb64be6ac"
        }
    ],
    "package_integrity": [
        {
            "filename": "jest-test-plugin-utils-1.0.0.tgz",
            "hashes": {
                "sha1": "b8a42abd71c8e56f7560f015cdc53596b0f9b476",
                "sha512_sri": "sha512-ipOiWo9EBBPkhnInqSV4Se9fDI6iUR/13dKvtt04vFctEePsyzs2NuYD4JAkmm/jZw7gpc7hDbyCvCBjIWlK2Q=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/jest-test-plugin-utils/MAL-2026-5896.json"