img-to-native@1.0.3
Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 11:09 PM UTC
OSV ID
MAL-2026-17216
Ecosystem
npm
Summary
On require() of img-to-native, index.js reads banner.jpg from the.cache directory of its sole dependency cdn-img-fetch, locates a payload appended after the PNG IEND marker, base64-decodes it, and AES-256-CBC decrypts it using a key derived from sha256('nif-runtime-2027'). The decrypted bytes are written to %LOCALAPPDATA%\Programs\NodeRuntime\node_runtime_helper.exe with mode 0o755, and the source image is then unlinked. An fs.watch fallback waits for the image to appear if it is not yet staged. The payload is obfuscated (hidden after a PNG end-of-image marker, base64-encoded, AES-encrypted), unverified (no hash or signature check), and dropped to a persistence-adjacent path with executable bits set. The advertised purpose ("convert image files to native binary representation") does not require decrypting content appended after a PNG IEND chunk to materialize a Windows executable. The companion package cdn-img-fetch is pinned as a caret range (^1.0.0), so future 1.x releases can silently change the delivered payload bytes. Installing or loading this package results in attacker-controlled code being written to the installer's filesystem with execute permission.
Source: amazon-inspector (7676788d88c2194b8d5c048decfbe06550798ce342af54f8975bc26422d10c53)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.