test-agency-assignment-01@1.0.5
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17296
Ecosystem
npm
Summary
The tarball contains only package.json and an 8.4 MB Go-compiled Windows executable, Kelimasow.exe (sha256 875c7641dc980538f3c3d8b344d173f97cf64a5d97dcf88d8e2932c83b876b92). package.json declares scripts.postinstall = "Kelimasow.exe", so npm install auto-executes this binary on any Windows host. The package has no library code (main points at a nonexistent index.js), no README, no source, no build system, and empty description/author/repository fields, so there is no advertised purpose that would justify shipping an opaque native executable and no way to inspect what the binary does before it runs. Auto-executing a bundled opaque native binary from a package lifecycle hook, with no accompanying source or declared purpose, is the canonical install-time-RCE dropper shape.
Source: amazon-inspector (2098eadf99f0ffe4dc04f478ed085034d30415cb52201be4f36f688298abc46e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.