parallely@10.0.4
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC
OSV ID
MAL-2026-11143
Ecosystem
npm
Summary
The npm package name parallely typosquats concurrently: package.json advertises the concurrently repository, author, and funding while shipping different code. On library load, an IIFE inside resolveShell in dist/lib/spawn.js reconstructs a hidden download URL at runtime by AES-256-GCM decrypting a hardcoded ciphertext (key XOR'd from four base64 constants; IV and auth tag hardcoded), then downloads a platform-specific payload (linux/mac binary or win.js) into os.tmpdir()/ins-<euid>/, sha256-verifies it against a fetched .meta, chmods it executable, strips the macOS quarantine attribute via xattr -c, and spawns it detached and unref'd. The same block installs anti-analysis guards: it silences uncaughtException/warning handlers, reads /proc/self/status to check TracerPid, calls inspector.url(), and scans env/argv for --inspect/--debug, short-circuiting if any debugger signal is present. A self-relaunch guarded by environment-variable tags is used to survive being imported versus exec'd. The C2 host is not present in plaintext; it is reconstructed only at runtime specifically to defeat static inspection.
Source: amazon-inspector (2a862cdceb2998828aba8de0d4a672b86a2c22dff073356e5acd89e894aced56)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.