MAL-2026-14277

    Dashboard / Malicious Package / MAL-2026-14277

    MAL-2026-14277

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in o0o9 (npm)

    Details: Source: amazon-inspector (a1d425848ef7172faf5f84ff9bd9017bf3ab1eb2343a5301ff0df1711d091118) The package's main entry index.js imports child_process at the top of the file and invokes spawn("powershell",...) as a top-level side effect (line 27). Loading the module via require/import causes an unprompted PowerShell process to launch on the installer's machine, which is a Windows-focused code execution vector wholly unrelated to any legitimate library function. This is the shape of an install/import-time execution payload rather than an API a caller must opt into.

    Affected packages

    Package

    Name: o0o9

    Purl: pkg:npm/o0o9

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.8.0
    MAL-2026-14277 | CVE-DB