{"id":"MAL-2026-14277","summary":"Malicious code in o0o9 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a1d425848ef7172faf5f84ff9bd9017bf3ab1eb2343a5301ff0df1711d091118)\nThe package's main entry index.js imports child_process at the top of the file and invokes spawn(\"powershell\",...) as a top-level side effect (line 27). Loading the module via require/import causes an unprompted PowerShell process to launch on the installer's machine, which is a Windows-focused code execution vector wholly unrelated to any legitimate library function. This is the shape of an install/import-time execution payload rather than an API a caller must opt into.\n","modified":"2026-08-19T08:00:10.823462322Z","published":"2026-08-19T07:21:14Z","database_specific":{"malicious-packages-origins":[{"sha256":"a1d425848ef7172faf5f84ff9bd9017bf3ab1eb2343a5301ff0df1711d091118","source":"amazon-inspector","versions":["1.8.0"],"id":"IN-MAL-2026-018390","import_time":"2026-08-19T07:48:47.011656424Z","modified_time":"2026-08-19T07:21:23Z"},{"source":"amazon-inspector","versions":["2.0.1"],"id":"IN-MAL-2026-018389","import_time":"2026-08-19T07:48:46.555687629Z","modified_time":"2026-08-19T07:21:14Z","sha256":"dc07d1bcb92034037f41bf30cf6bd67f5313276df6aeef3a805d4b52d757e22b"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/o0o9/v/1.8.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/o0o9/v/2.0.1"}],"affected":[{"package":{"name":"o0o9","ecosystem":"npm","purl":"pkg:npm/o0o9"},"versions":["1.8.0","2.0.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-WL73hRdoiMONJnxdZnOQgCJgCjF8vKEL/qo3QYe1sNLmRPUes3VF4de7lYLQGCFQOtySVoWedabEsS8Atb8PgA==","sha1":"f184b39b51a2634201d269dd8dcdaa1657264b37"},"filename":"o0o9-2.0.1.tgz"}],"evidence_files":[{"path":"index.js","sha256":"3d021550c3cc60b53cc3ba05c56418eb3012fca19f2496a156c6730736a47a93","tlsh":"1e318736639b6d34a2314990a856642b689fc130736424d0d51c713bff1b83b42779dd"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/o0o9/MAL-2026-14277.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}