Skip to main content

Threats Tagged 'mal-2026-10176'

View all threats tagged with 'mal-2026-10176'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: mal-2026-10176

Threats Tagged 'mal-2026-10176'

Click on any threat for detailed analysis and mitigation recommendations

0

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (acda9720ae54881219c0fbcee73795be85877d292aa62662f7cb6b92e775f608) Package ships an obfuscated dist/index.js that is invoked from the postinstall lifecycle hook (`node dist/index.js`). At install time, the script performs an HTTPS GET to https://onch.cc/test1.txt (and https://onch.cc/test2.txt), base64-decodes the response body, and executes it via `new Function('require', decoded)()`, granting the fetched code full Node.js capabilities (including `require`) on the installer's machine. The dropper is gated by `process.env.P == 1`, allowing the attacker to keep the payload dormant on incidental installers and detonate selectively (e.g., on CI runners where P is set). The fetching logic is obfuscated using javascript-obfuscator (hex identifiers, rotating string array, decoder wrapper), and the package's own build script (`"obfuscate": "javascript-obfuscator./dist/index.js..."`) confirms obfuscation is applied deliberately before publish. The remote host onch.cc is unrelated to any documented package purpose (the package has no README), and the fetched content is opaque, mutable, and unpinned. This is a classic install-time RCE dropper with attacker-controlled remote code execution on `npm install`.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: mal-2026-10176
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses