MAL-2026-14292Malicious code in log-res (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | log-res | 1.0.3 |
{"modified":"2026-08-19T08:23:09Z","published":"2026-08-19T08:23:09Z","schema_version":"1.7.4","id":"MAL-2026-14292","summary":"Malicious code in log-res (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (59f23ea1c6c40021fb69210eba68cdbda94b42f4e255f78758778b90ebb09d78)\nindex.js re-exports a `desKey` string sourced from apps/docs/app/theta.js, which reads apps/docs/app/des.db as UTF-8. des.db contains a heavily obfuscated JavaScript program (string-array + hex-name mangling) that, when evaluated, creates a directory under the OS temp directory, writes a synthetic package.json declaring runtime dependencies on axios, better-sqlite3, node-machine-id, and socket.io-client, spawns `npm install` inside that directory, and then spawns `node` on a staged index.js. The payload is disguised as a database file (`des.db`) rather than shipped as source, and the stager fetches and runs a socket.io-client-based remote agent capable of receiving commands from an attacker-controlled endpoint. The package's advertised purpose (a docs/monorepo TheData API helper) does not require embedding or exporting an obfuscated executable blob.\n","affected":[{"package":{"ecosystem":"npm","name":"log-res"},"versions":["1.0.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"apps/docs/app/theta.js","sha256":"248e883a193f21ac7d1eb48fa7541513fbc381620d03957e7e70c8fa359d0984","tlsh":"cfd022c20c0f03888ee15b98950e60620bb300083b80d6a1f47d8f30302b488f55a29c"},{"path":"apps/docs/app/des.db","sha256":"969e68faa42267ab57e154d6032b4009272b04ac76f28672dc97ecc1fa7585ba","tlsh":"c2f2c8cc3f81f3e46213b0bb6e1aa4d5e1699cd8bd8d8048f356b458f958324e1bdb19"}],"package_integrity":[{"filename":"log-res-1.0.3.tgz","hashes":{"sha1":"d265c04001e0ec8f495dd630c13dabacd0b810c0","sha512_sri":"sha512-VYZZkum8ubdiwhuGhTeSBO2ZoIhbQGY1f6YiQHVMCKMJ70wPCA1LwsmiBgZG/FB6IvB9rAsdvPpxJQ1+R11e9A=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/log-res/v/1.0.3"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018407","import_time":"2026-08-19T08:48:53.617406895Z","modified_time":"2026-08-19T08:23:09Z","sha256":"59f23ea1c6c40021fb69210eba68cdbda94b42f4e255f78758778b90ebb09d78","source":"amazon-inspector","versions":["1.0.3"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0