test-agency-assign@1.0.4
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17295
Ecosystem
npm
Summary
test-agency-assign@1.0.4 declares a package.json postinstall script wscript.exe Kelimasow.exe that auto-executes a bundled 8.4 MB Go-compiled Windows PE (Kelimasow.exe, sha256 875c7641dc980538f3c3d8b344d173f97cf64a5d97dcf88d8e2932c83b876b92) on npm install. The package has no README, empty description and author fields, no source code, and no other functional content — the manifest is a thin wrapper whose sole install-time effect is to execute an opaque native binary on the installer's machine. Opaque binary + lifecycle-hook auto-execution + missing metadata is the canonical install-time RCE / dropper packaging shape, giving whoever published this arbitrary code execution on any Windows host that installs the package.
Source: amazon-inspector (e650e815b4409c3c07cdab7c953ed69b8052f32a28c3686397ab362bb1bd4552)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.