VDB
Sign up
—

MAL-2026-17216

Malicious code in img-to-native (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (0958774b99a66f77dcdc9730f565a259d419d9e863315e10160960c538377717) On require of img-to-native, index.js polls %TMP%\._cif_data for a PNG file staged by the declared companion dependency cdn-img-fetch, locates a `//BIN//` marker placed after the PNG IEND chunk, base64-decodes and AES-256-CBC-decrypts the trailing blob using a hardcoded 32-byte key derived from the ASCII string 'malfexteam2027', and writes the resulting executable to %APPDATA%\Microsoft\Windows\node_runtime_helper.exe with mode 0700, masquerading as a legitimate Node runtime helper in a system-adjacent Windows path. The fetch of the encrypted payload and the decryption/drop are split across two npm packages (cdn-img-fetch stages the PNG, img-to-native decrypts and drops the binary); the shipped code is inert without the companion write and coordinates via a temp-file poll loop with a ~2-minute wait. Steganographic concealment of the payload inside a PNG plus AES encryption with a hardcoded key is deliberate obfuscation to bypass content scanning, and the README's declared file-copy purpose does not match the dropper behavior.

## Source: ghsa-malware (7131e9cb1bdeb272ae7e26f2877087fd5da8716ef7c08e0fc0bf1359e278df8e) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/img-to-native
Introduced in: 0

No fixed version published yet for img-to-native (npm). Pin to a known-safe version or switch to an alternative.

References