img-to-native@1.0.1
Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 8:08 PM UTC
OSV ID
MAL-2026-17216
Ecosystem
npm
Summary
On require of img-to-native, index.js polls %TMP%\._cif_data for a PNG file staged by the declared companion dependency cdn-img-fetch, locates a //BIN// marker placed after the PNG IEND chunk, base64-decodes and AES-256-CBC-decrypts the trailing blob using a hardcoded 32-byte key derived from the ASCII string 'malfexteam2027', and writes the resulting executable to %APPDATA%\Microsoft\Windows\node_runtime_helper.exe with mode 0700, masquerading as a legitimate Node runtime helper in a system-adjacent Windows path. The fetch of the encrypted payload and the decryption/drop are split across two npm packages (cdn-img-fetch stages the PNG, img-to-native decrypts and drops the binary); the shipped code is inert without the companion write and coordinates via a temp-file poll loop with a ~2-minute wait. Steganographic concealment of the payload inside a PNG plus AES encryption with a hardcoded key is deliberate obfuscation to bypass content scanning, and the README's declared file-copy purpose does not match the dropper behavior.
Source: amazon-inspector (0958774b99a66f77dcdc9730f565a259d419d9e863315e10160960c538377717)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.