MAL-2026-17317

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/booking-tasks/MAL-2026-17317.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17317
Published
2026-09-30T03:05:04Z
Modified
2026-09-30T03:30:04Z
Summary
Malicious code in booking-tasks (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (08305a6c73bd94f2983c949316cb78fef7f7169f85523a773c94fb305874e063)

The package's package.json declares a postinstall hook wscript.exe 4444.vbs that fires automatically on npm install. The bundled 4444.vbs contains hand-rolled AES-128 (with XOR-masked forward/inverse S-boxes), a ChaCha20-IETF stream, XOR-masked SHA-256 round constants, a Base64 decoder via MSXML DOM, and a chunked Base64 ciphertext blob (ArtifactBundleHX, ~665 chunks). At install time the VBScript decrypts these chunks into a PowerShell loader, writes it to %TEMP%\pf.dat, and hands it to powershell.exe for process hollowing, giving the publisher arbitrary code execution on the installer's Windows host. The shipped library surface (src/index.js) is a small Zod-validated checkEligibility() function that never references 4444.vbs, and readme.md states 'No network requests. No personal data storage. No installation scripts.' — a direct contradiction of the declared postinstall hook, indicating the source module is a decoy for the dropper. The multi-primitive crypto and chunked-Base64 encoding of the payload serve only to hide executable content from static inspection.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020796",
            "import_time":  "2026-09-30T03:24:19.763928517Z",
            "modified_time":  "2026-09-30T03:05:04Z",
            "sha256":  "08305a6c73bd94f2983c949316cb78fef7f7169f85523a773c94fb305874e063",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / booking-tasks

Package

Name
booking-tasks
View open source insights on deps.dev
Purl
pkg:npm/booking-tasks

Affected ranges

Affected versions

1.*
1.0.2

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "82955201b82d99a4d3d85add5d558db7f3758a0cf1295236f7ada79c5a888429",
            "tlsh":  "fce02213ca549f6722f8a7a2ad354213b2690f0f02614d0b30fb126c4f612b720dfb6c"
        },
        {
            "path":  "4444.vbs",
            "sha256":  "89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a",
            "tlsh":  "daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8"
        },
        {
            "path":  "readme.md",
            "sha256":  "11f2ec1d479385714632f19967af06a5273b66baf7ffab8c9f9e400092735026",
            "tlsh":  "3c3100444c23e37935b1e31bbc90b092e7f4915c0aa60c51b9aa835e1315f62fb7f84e"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "booking-tasks-1.0.2.tgz",
            "hashes":  {
                "sha1":  "c2b0bb45d34ea57f155ecdba8396dbf334bf3aee",
                "sha512_sri":  "sha512-7xSqKU/aEEOdTui/UMTLIjVPSfK5qnCBk8J/A27R/Lq8ugHidyT8PzgVDNyP8ix79U/6Y6ousl8ptpBydgDMPQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/booking-tasks/MAL-2026-17317.json"