random-certs@0.0.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC
OSV ID
MAL-2026-17644
Ecosystem
npm
Summary
random-certs@0.0.1 ships a file named sample/cert.pem that is not a certificate but base64-encoded JavaScript wrapped in BEGIN/END CERTIFICATE markers. The exported generateCertificates() in index.js strips those markers, base64-decodes the body, and eval()s the result. The recovered JavaScript fetches a hardcoded Google Drive URL (https://drive.usercontent.google.com/download?id=1y4LSiUb4PZSGjKBtEVJMDMnl3Sr7kbSy) and pipes the response into a detached, window-hidden python3 - (or python on Windows) process via stdin, executing the downloaded bytes as Python on the host. The destination URL is itself base64-nested inside the fake PEM to further hide it. A certificate-generation API covertly resolving to remote Python execution from an attacker-controlled location, with multiple layers of disguise, is a deliberate malicious payload rather than a legitimate helper.
Source: amazon-inspector (9077ef856afc462f5d7c757a14ee2c9633386c3809e58e8f725310a33dd35112)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.