MAL-2026-14277Malicious code in o0o9 (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | o0o9 | 1.8.0 |
| npm | o0o9 | 2.0.1 |
{"modified":"2026-08-19T07:50:57Z","published":"2026-08-19T07:21:14Z","schema_version":"1.7.4","id":"MAL-2026-14277","summary":"Malicious code in o0o9 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a1d425848ef7172faf5f84ff9bd9017bf3ab1eb2343a5301ff0df1711d091118)\nThe package's main entry index.js imports child_process at the top of the file and invokes spawn(\"powershell\",...) as a top-level side effect (line 27). Loading the module via require/import causes an unprompted PowerShell process to launch on the installer's machine, which is a Windows-focused code execution vector wholly unrelated to any legitimate library function. This is the shape of an install/import-time execution payload rather than an API a caller must opt into.\n","affected":[{"package":{"ecosystem":"npm","name":"o0o9"},"versions":["1.8.0","2.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"3d021550c3cc60b53cc3ba05c56418eb3012fca19f2496a156c6730736a47a93","tlsh":"1e318736639b6d34a2314990a856642b689fc130736424d0d51c713bff1b83b42779dd"}],"package_integrity":[{"filename":"o0o9-2.0.1.tgz","hashes":{"sha1":"f184b39b51a2634201d269dd8dcdaa1657264b37","sha512_sri":"sha512-WL73hRdoiMONJnxdZnOQgCJgCjF8vKEL/qo3QYe1sNLmRPUes3VF4de7lYLQGCFQOtySVoWedabEsS8Atb8PgA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/o0o9/v/1.8.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/o0o9/v/2.0.1"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018390","import_time":"2026-08-19T07:48:47.011656424Z","modified_time":"2026-08-19T07:21:23Z","sha256":"a1d425848ef7172faf5f84ff9bd9017bf3ab1eb2343a5301ff0df1711d091118","source":"amazon-inspector","versions":["1.8.0"]},{"id":"IN-MAL-2026-018389","import_time":"2026-08-19T07:48:46.555687629Z","modified_time":"2026-08-19T07:21:14Z","sha256":"dc07d1bcb92034037f41bf30cf6bd67f5313276df6aeef3a805d4b52d757e22b","source":"amazon-inspector","versions":["2.0.1"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0