-= Per source details. Do not edit below this line.=-
Package ships a single ~138 KB browser script whose entire body is an RC4-encrypted base64 blob decoded at runtime by an inline RC4 routine (_zc) with a DJB2 helper (_zh) and a key reconstructed by XORing a numeric array with 1410^714. Before decryption the script performs anti-analysis guards: a devtools-size heuristic (if(_gz>160||_gp>160)return;) that aborts execution when developer tools are open, and a block that overwrites console.log/info/warn/debug/error to no-ops to suppress runtime tracing. The package name contoso-login-sim-loader self-describes as a 'login sim(ulator) loader' while the published description reframes it as a generic 'Client-side asset loader that renders a self-contained UI component when included via a script tag.' The tarball ships no source, no exports, no dependencies, and no documentation - only the opaque encrypted payload. Any site that follows the include-via-script-tag guidance embeds attacker-controlled JavaScript, decrypted only in end-user browsers, into its own pages; the concealed payload cannot be audited without executing it, and the name plus cover-story description are consistent with a fake-login/credential-harvest overlay served to that site's visitors.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020808",
"import_time": "2026-09-30T04:46:52.569286275Z",
"modified_time": "2026-09-30T04:40:31Z",
"sha256": "062ce76699c91a883d24e3ad609bb04faa3f52cbeaecfb24c1c3bcde8b496a5c",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "obfuscated_loader.js",
"sha256": "090956991144179b8202c6a3c09917b6e373467729fdc1ded76fc7362bce0287",
"tlsh": "c8d313e32a7d8e7d3a60b45b162d7a277742de5a80c9d9f8f3972cc9805678e01f1b04"
},
{
"path": "package.json",
"sha256": "e13b1866380f8e87252fe99ed53d15371fa27b591c60b857b7d8ab3411216d63",
"tlsh": "4ff05c28ed25dc2210c4d5194966e826d954adbb8382bc1d3397d40ccfcc26bd0bf5dd"
}
],
"package_integrity": [
{
"filename": "contoso-login-sim-loader-1.0.1.tgz",
"hashes": {
"sha1": "344f0c973ada73adb83e4c98287dddc35dd12db9",
"sha512_sri": "sha512-vEe4MbH2x7pQTx4odQnDxR1x6I3Id/4vzfbNLuYCRf3wexFTk+5JkSm28Lkh+YpZUmG3P+eXb+zcRqRGhsQjow=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/contoso-login-sim-loader/MAL-2026-17322.json"