-= Per source details. Do not edit below this line.=-
package.json declares a postinstall lifecycle script wscript.exe 4444.vbs, causing the VBS file shipped in the tarball to run automatically on npm install on Windows hosts. 4444.vbs contains a hand-rolled multi-layer decoder (Base64, an XOR-masked AES S-box, ChaCha20-IETF, additional XOR) that concatenates hundreds of embedded ~2KiB Base64 chunks stored in ArtifactBundleHX(...), decrypts them, writes the resulting PowerShell loader to a randomly named file under %TEMP% (pf<rand>.dat), and invokes powershell.exe against it. In-file comments describe the handoff to PowerShell as being for process hollowing. The file header presents a benign 'Device Telemetry Aggregator' cover story that does not match the shipped behavior. The package's only functional content is this dropper; installing the package on Windows results in arbitrary attacker-controlled code execution on the installer's host.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020611",
"import_time": "2026-09-28T22:18:22.479197758Z",
"modified_time": "2026-09-28T22:03:04Z",
"sha256": "dcdf62e1c1eb44ca7a29ed37c12bdb71883025a46c5066e58c9228f0dfe782c2",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "60b89a83cb5dfa6b32a01f4332fed1392196cc0d4b668322e8badcd2142d36e6",
"tlsh": "90d0a7274945963329f4475409718416b5128f1f10314c0bb2f3651890e36b24889b06"
},
{
"path": "4444.vbs",
"sha256": "89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a",
"tlsh": "daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8"
}
],
"package_integrity": [
{
"filename": "test-agency-assignment-1.0.2.tgz",
"hashes": {
"sha1": "75c09d06aa8e36ddb9c4fa79ae9359625bf338b9",
"sha512_sri": "sha512-QFNwa4A6D07b6XzW/pZORsllAx2DWxB0CtbT8z32V/4gghmBVQQaWJ8Ik92AUwhsI+3JLYYI3R2+9Ava6LSRxA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-agency-assignment/MAL-2026-17239.json"