contoso-login-sim-loader@1.0.1
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17322
Ecosystem
npm
Summary
Package ships a single ~138 KB browser script whose entire body is an RC4-encrypted base64 blob decoded at runtime by an inline RC4 routine (_zc) with a DJB2 helper (_zh) and a key reconstructed by XORing a numeric array with 1410^714. Before decryption the script performs anti-analysis guards: a devtools-size heuristic (if(_gz>160||_gp>160)return;) that aborts execution when developer tools are open, and a block that overwrites console.log/info/warn/debug/error to no-ops to suppress runtime tracing. The package name contoso-login-sim-loader self-describes as a 'login sim(ulator) loader' while the published description reframes it as a generic 'Client-side asset loader that renders a self-contained UI component when included via a script tag.' The tarball ships no source, no exports, no dependencies, and no documentation - only the opaque encrypted payload. Any site that follows the include-via-script-tag guidance embeds attacker-controlled JavaScript, decrypted only in end-user browsers, into its own pages; the concealed payload cannot be audited without executing it, and the name plus cover-story description are consistent with a fake-login/credential-harvest overlay served to that site's visitors.
Source: amazon-inspector (062ce76699c91a883d24e3ad609bb04faa3f52cbeaecfb24c1c3bcde8b496a5c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.