-= Per source details. Do not edit below this line.=-
The package advertises itself as a Jest plugin (name: 'jest-test-plugin-utils', description: 'mqtt utils') but ships no Jest or MQTT functionality. Its main entry dist/index.js is a heavily obfuscated 200KB browserify bundle (obfuscator.io fingerprint: 1299-entry rotated string array, decoder wrapper, control-flow flattening; built with the declared devDependency 'gulp-javascript-obfuscator'). After deobfuscation, the only meaningful behavior is a function loadFilbetScriptSilently() (exposed as window.fetchFilbetScript) that creates a
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-006765",
"import_time": "2026-06-16T16:06:34.427097256Z",
"modified_time": "2026-06-16T15:37:24Z",
"sha256": "3f948eff13632557a65152c587b6aa87783e49cf40504aedca8ee15da6ed205e",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-006764",
"import_time": "2026-06-16T16:06:34.332185997Z",
"modified_time": "2026-06-16T15:37:23Z",
"sha256": "54c5196f3361da72dfccd2c8abb0caba132415f9907602c5a6ec92d6da2e077f",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-006766",
"import_time": "2026-06-16T16:06:34.568829617Z",
"modified_time": "2026-06-16T15:37:30Z",
"sha256": "bb80fa98045e0dd75514425f419aa986e7e57bfa888d8baaa8c5eb0016418f83",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-006763",
"import_time": "2026-06-16T16:06:34.127682958Z",
"modified_time": "2026-06-16T15:37:20Z",
"sha256": "f5445eba984ab32829120583a68c6bfc2fa8aec2f875b506c873de598f1d27d1",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"id": "GHSA-7969-jc8h-fp32",
"import_time": "2026-08-20T13:33:26.043107536Z",
"modified_time": "2026-08-20T13:05:33Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "951d82ab1573c962c8c548477013f418229d33a24e4e6a89e509ca4fdb149106",
"source": "ghsa-malware"
},
{
"id": "IN-MAL-2026-018464",
"import_time": "2026-08-20T21:43:25.339148887Z",
"modified_time": "2026-08-20T21:14:38Z",
"sha256": "149fc5043ae3e73f200138c8c6c88106df7b187c2e08d6ad0dc7e889721de28b",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "dist/index.js",
"sha256": "a61584375c14c072e01ec862ed28d36ff0157245a5b195229da9dafa8946a040",
"tlsh": "e514404077c0b844538b1fba766fb4e5e46b1de934c4090bc515fca0f5baa26fae2934"
},
{
"path": "package.json",
"sha256": "b152b66b1f3a7e2634d7dcdb3cf45409e2fa55d9770b061f6f6f5c92db06f513",
"tlsh": "fdf02734dd71987306e820e51c682167e0709d2bc245fd1c33c7140c4a5f2eb64be6ac"
}
],
"package_integrity": [
{
"filename": "jest-test-plugin-utils-1.0.0.tgz",
"hashes": {
"sha1": "b8a42abd71c8e56f7560f015cdc53596b0f9b476",
"sha512_sri": "sha512-ipOiWo9EBBPkhnInqSV4Se9fDI6iUR/13dKvtt04vFctEePsyzs2NuYD4JAkmm/jZw7gpc7hDbyCvCBjIWlK2Q=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/jest-test-plugin-utils/MAL-2026-5896.json"