MAL-2026-14303
Malicious code in x6842179305 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (ca4cf1d317cc7c96f8007c983999e18529f2cb8dea5514dcc68f704c7bda5638) Package x6842179305 ships a main entry (1.js) that invokes the `Function` constructor over a custom-encoded, keyed/XOR-decoded byte buffer, causing an opaque payload to execute whenever the module is required or imported. A sibling file (ui.js) contains a matching custom-alphabet decoder feeding another opaque byte stream. The runtime behavior of the decoded payload — including any network destinations, credential access, or filesystem writes — is not statically determinable because the code has no readable source form. The package name is a numeric burner-style identifier with no documented purpose, no README describing functionality, and no legitimate library shape (no exported API surface, no source tree). A Function()-constructor executor over a custom-encoded byte table on module load has no benign engineering rationale and matches the obfuscated-loader / dropper pattern used to hide install- or import-time payloads from static review.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for x6842179305 (npm). Pin to a known-safe version or switch to an alternative.