-= Per source details. Do not edit below this line.=-
The tarball contains only package.json and 4444.vbs; the declared main entry (index.js) is absent. package.json defines a postinstall script wscript.exe 4444.vbs, so on npm install on Windows the VBScript executes automatically. 4444.vbs is heavily obfuscated (colon-delimited XOR-encoded CreateObject strings, embedded AES S-box and ChaCha20-IETF routines, and 600+ base64 fragments reconstructed at runtime) and presents cover strings identifying itself as Device Telemetry Aggregator / Verdant Signals Corp.. It reconstructs an encrypted payload, writes it to %TEMP% as a pf*.dat file, and invokes powershell.exe to perform process hollowing of the decoded loader. The package ships no library code — its only reachable behavior is the install-time dropper.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020692",
"import_time": "2026-09-29T23:17:35.356841763Z",
"modified_time": "2026-09-29T23:05:45Z",
"sha256": "e9944ea8ca21c0670c4b718a12427e8ca7330571ef5a9198a60b05f75038fe73",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "ab92d275016fd5c87f726eaacc6d7a83ad87f62002a4cee7a07de79a8ee8ef5c",
"tlsh": "01d0a7274945563369f446640935991ab5128f2f51314c0bb2f3651890e37b24889b06"
},
{
"path": "4444.vbs",
"sha256": "89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a",
"tlsh": "daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8"
}
],
"package_integrity": [
{
"filename": "test-agency-assignment-02-1.0.5.tgz",
"hashes": {
"sha1": "02e66c207376d2e743cca7df0001733c0d24fb53",
"sha512_sri": "sha512-pPlsB2BA0XQxORXa91N7mwr/AxfDsnPgfW/jddsANiFpHMcPNP+91cIojl+spJej3DfUTosTyNnV7sbB6hdKBA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-agency-assignment-02/MAL-2026-17297.json"