MAL-2026-14277
Malicious code in o0o9 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (a1d425848ef7172faf5f84ff9bd9017bf3ab1eb2343a5301ff0df1711d091118) The package's main entry index.js imports child_process at the top of the file and invokes spawn("powershell",...) as a top-level side effect (line 27). Loading the module via require/import causes an unprompted PowerShell process to launch on the installer's machine, which is a Windows-focused code execution vector wholly unrelated to any legitimate library function. This is the shape of an install/import-time execution payload rather than an API a caller must opt into.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for o0o9 (npm). Pin to a known-safe version or switch to an alternative.
References
- https://www.npmjs.com/package/o0o9/v/1.8.0 [PACKAGE]
- https://www.npmjs.com/package/o0o9/v/2.0.1 [PACKAGE]