MAL-2026-17332

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/runhelper/MAL-2026-17332.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17332
Published
2026-09-30T05:29:04Z
Modified
2026-09-30T06:00:07Z
Summary
Malicious code in runhelper (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (3b30a78c30f51a72d8501b77d0cf6190319b8876ed7a119cc2f885adc3618212)

On require('runhelper'), index.js unconditionally loads a payload file staged by its dependency imgbundle at cdn-img-fetch/.runtime/rt.jpg, allocates executable memory via kernel32 VirtualAlloc with PAGE_EXECUTE_READWRITE (0x40) and MEM_COMMIT|MEM_RESERVE (0x3000) through the koffi FFI, copies the file bytes with RtlMoveMemory, and executes them with CreateThread. The payload file is deleted after launch, and an fs.watch waits for it if not yet present. The .jpg extension in a hidden .runtime directory disguises an executable payload, and all errors are swallowed with empty catch (_) {} blocks. The advertised exec() spawn wrapper described in the README is a cover story: the module's top-level behavior on load is native shellcode execution. The manifest pins imgbundle@^1.0.0 (payload source) and koffi@^2.8.0 (FFI used to run it); the loader/payload split means anything that transitively requires runhelper on Windows fetches and executes attacker-supplied native code in-process.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-020819",
            "import_time": "2026-09-30T05:44:17.259385457Z",
            "modified_time": "2026-09-30T05:29:04Z",
            "sha256": "3b30a78c30f51a72d8501b77d0cf6190319b8876ed7a119cc2f885adc3618212",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / runhelper

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "index.js",
            "sha256": "a0e7dbbef7b47e3f9641ee1896b0a7b0005c66e5b8b3a51fa661cfeffc6816a0",
            "tlsh": "3a31134606f73671646361e95a1b9449a09bd463326ae570bcdd83802f67254c7329fc"
        }
    ],
    "package_integrity": [
        {
            "filename": "runhelper-1.0.0.tgz",
            "hashes": {
                "sha1": "b10393e9a3abaccc26fba84cfbbffeb3ec22a91a",
                "sha512_sri": "sha512-acJRuBBDX0AVzguTtk4qcTtQVYo2ngAOQlIdRtb8Lgp7kBtlFLt4paytylSExwrLu+8RIcByIs+8sf0NzlK1vA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/runhelper/MAL-2026-17332.json"