imgbundle@1.0.1
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 7:13 AM UTC
OSV ID
MAL-2026-17330
Ecosystem
npm
Summary
The package advertises itself as an image bundler, but index.js performs no image bundling. On require, a top-level IIFE reads an AES-256-CBC-encrypted file at cdn-img-fetch/.cache/banner.jpg inside the sibling dependency cdn-img-fetch, decrypts it with a hardcoded key derived from sha256('nif-runtime-2027'), writes the plaintext to cdn-img-fetch/.runtime/rt.jpg, deletes the source file, and registers an fs.watch on the source directory so the decrypt-and-stage step still fires if the encrypted blob is delivered later. The package also calls cif.ensureCached() on the cdn-img-fetch dependency in an error-recovery path, wiring the two packages together as a coordinated staged dropper: cdn-img-fetch supplies the encrypted bytes and imgbundle acts as the decoder that materializes attacker-controlled content onto the installer's filesystem at import time. The README description of image bundling does not correspond to any code path in the module, and hardcoded-AES-key decryption of an opaque blob from another package is not a legitimate implementation of that stated purpose.
Source: amazon-inspector (e14218599b46d143fa8e150156864d14d58c327bd8a8816221ac4e8c5cc99350)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.