Logo
npm

test-agency-assignment-01@1.0.5

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17296

Ecosystem

npm

Summary

The tarball contains only package.json and an 8.4 MB Go-compiled Windows executable, Kelimasow.exe (sha256 875c7641dc980538f3c3d8b344d173f97cf64a5d97dcf88d8e2932c83b876b92). package.json declares scripts.postinstall = "Kelimasow.exe", so npm install auto-executes this binary on any Windows host. The package has no library code (main points at a nonexistent index.js), no README, no source, no build system, and empty description/author/repository fields, so there is no advertised purpose that would justify shipping an opaque native executable and no way to inspect what the binary does before it runs. Auto-executing a bundled opaque native binary from a package lifecycle hook, with no accompanying source or declared purpose, is the canonical install-time-RCE dropper shape.

Source: amazon-inspector (2098eadf99f0ffe4dc04f478ed085034d30415cb52201be4f36f688298abc46e)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.