{"id":"MAL-2026-17322","summary":"Malicious code in contoso-login-sim-loader (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (062ce76699c91a883d24e3ad609bb04faa3f52cbeaecfb24c1c3bcde8b496a5c)\nPackage ships a single ~138 KB browser script whose entire body is an RC4-encrypted base64 blob decoded at runtime by an inline RC4 routine (`_zc`) with a DJB2 helper (`_zh`) and a key reconstructed by XORing a numeric array with 1410^714. Before decryption the script performs anti-analysis guards: a devtools-size heuristic (`if(_gz\u003e160||_gp\u003e160)return;`) that aborts execution when developer tools are open, and a block that overwrites `console.log/info/warn/debug/error` to no-ops to suppress runtime tracing. The package name `contoso-login-sim-loader` self-describes as a 'login sim(ulator) loader' while the published description reframes it as a generic 'Client-side asset loader that renders a self-contained UI component when included via a script tag.' The tarball ships no source, no exports, no dependencies, and no documentation - only the opaque encrypted payload. Any site that follows the include-via-script-tag guidance embeds attacker-controlled JavaScript, decrypted only in end-user browsers, into its own pages; the concealed payload cannot be audited without executing it, and the name plus cover-story description are consistent with a fake-login/credential-harvest overlay served to that site's visitors.\n","modified":"2026-09-30T05:00:12.398324144Z","published":"2026-09-30T04:40:31Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-30T04:46:52.569286275Z","modified_time":"2026-09-30T04:40:31Z","sha256":"062ce76699c91a883d24e3ad609bb04faa3f52cbeaecfb24c1c3bcde8b496a5c","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-020808"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/contoso-login-sim-loader/v/1.0.1"}],"affected":[{"package":{"name":"contoso-login-sim-loader","ecosystem":"npm","purl":"pkg:npm/contoso-login-sim-loader"},"versions":["1.0.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"obfuscated_loader.js","sha256":"090956991144179b8202c6a3c09917b6e373467729fdc1ded76fc7362bce0287","tlsh":"c8d313e32a7d8e7d3a60b45b162d7a277742de5a80c9d9f8f3972cc9805678e01f1b04"},{"tlsh":"4ff05c28ed25dc2210c4d5194966e826d954adbb8382bc1d3397d40ccfcc26bd0bf5dd","path":"package.json","sha256":"e13b1866380f8e87252fe99ed53d15371fa27b591c60b857b7d8ab3411216d63"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-vEe4MbH2x7pQTx4odQnDxR1x6I3Id/4vzfbNLuYCRf3wexFTk+5JkSm28Lkh+YpZUmG3P+eXb+zcRqRGhsQjow==","sha1":"344f0c973ada73adb83e4c98287dddc35dd12db9"},"filename":"contoso-login-sim-loader-1.0.1.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/contoso-login-sim-loader/MAL-2026-17322.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}