MAL-2026-12357

    Dashboard / Malicious Package / MAL-2026-12357

    MAL-2026-12357

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in cors-security (npm)

    Details: Source: amazon-inspector (b1cff2c95bb175e36d5cb7a6e4880ed0f8816cbfb1dc7acef5d8173cf2cc40bb) The CommonJS entry point of [email protected] exposes a getPlugin() API that issues an HTTPS GET to the hardcoded host workconfig.vercel.app and passes the response body directly to new Function('require', data)(require), running attacker-controlled JavaScript inside the consumer's Node process with access to require. TLS certificate verification is disabled on that request (rejectUnauthorized: false). The remote-loader code is present only in the CJS entry and absent from the ESM variant, and does not relate to the package's advertised SVG-utility purpose (name svgcraft, description "Professional zero-dependency SVG utilities"). Any consumer that requires the package and invokes the returned function executes whatever content the operator of workconfig.vercel.app serves at that moment.

    Affected packages

    Package

    Name: cors-security

    Purl: pkg:npm/cors-security

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1