MAL-2026-17322

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/contoso-login-sim-loader/MAL-2026-17322.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17322
Published
2026-09-30T04:40:31Z
Modified
2026-09-30T05:00:12Z
Summary
Malicious code in contoso-login-sim-loader (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (062ce76699c91a883d24e3ad609bb04faa3f52cbeaecfb24c1c3bcde8b496a5c)

Package ships a single ~138 KB browser script whose entire body is an RC4-encrypted base64 blob decoded at runtime by an inline RC4 routine (_zc) with a DJB2 helper (_zh) and a key reconstructed by XORing a numeric array with 1410^714. Before decryption the script performs anti-analysis guards: a devtools-size heuristic (if(_gz>160||_gp>160)return;) that aborts execution when developer tools are open, and a block that overwrites console.log/info/warn/debug/error to no-ops to suppress runtime tracing. The package name contoso-login-sim-loader self-describes as a 'login sim(ulator) loader' while the published description reframes it as a generic 'Client-side asset loader that renders a self-contained UI component when included via a script tag.' The tarball ships no source, no exports, no dependencies, and no documentation - only the opaque encrypted payload. Any site that follows the include-via-script-tag guidance embeds attacker-controlled JavaScript, decrypted only in end-user browsers, into its own pages; the concealed payload cannot be audited without executing it, and the name plus cover-story description are consistent with a fake-login/credential-harvest overlay served to that site's visitors.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-020808",
            "import_time": "2026-09-30T04:46:52.569286275Z",
            "modified_time": "2026-09-30T04:40:31Z",
            "sha256": "062ce76699c91a883d24e3ad609bb04faa3f52cbeaecfb24c1c3bcde8b496a5c",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / contoso-login-sim-loader

Package

Name
contoso-login-sim-loader
View open source insights on deps.dev
Purl
pkg:npm/contoso-login-sim-loader

Affected ranges

Affected versions

1.*
1.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "obfuscated_loader.js",
            "sha256": "090956991144179b8202c6a3c09917b6e373467729fdc1ded76fc7362bce0287",
            "tlsh": "c8d313e32a7d8e7d3a60b45b162d7a277742de5a80c9d9f8f3972cc9805678e01f1b04"
        },
        {
            "path": "package.json",
            "sha256": "e13b1866380f8e87252fe99ed53d15371fa27b591c60b857b7d8ab3411216d63",
            "tlsh": "4ff05c28ed25dc2210c4d5194966e826d954adbb8382bc1d3397d40ccfcc26bd0bf5dd"
        }
    ],
    "package_integrity": [
        {
            "filename": "contoso-login-sim-loader-1.0.1.tgz",
            "hashes": {
                "sha1": "344f0c973ada73adb83e4c98287dddc35dd12db9",
                "sha512_sri": "sha512-vEe4MbH2x7pQTx4odQnDxR1x6I3Id/4vzfbNLuYCRf3wexFTk+5JkSm28Lkh+YpZUmG3P+eXb+zcRqRGhsQjow=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/contoso-login-sim-loader/MAL-2026-17322.json"