MAL-2026-17511

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/lite-mater/MAL-2026-17511.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17511
Published
2026-10-04T23:27:22Z
Modified
2026-10-04T23:45:18Z
Summary
Malicious code in lite-mater (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (532663c4102d3cf7310e29ca1eb2b389c5c32c1e541da219b7c4364968f4e807)

package.json declares a postinstall lifecycle hook wscript.exe 4444.vbs that runs automatically on npm install on Windows hosts. The shipped 4444.vbs (~765 KB) is a multi-layer obfuscated loader: an embedded payload is stored as a large ArtifactBundleHX[] string array, Base64-decoded via MSXML DOM into a byte buffer, then decrypted through a custom XOR routine, an AES forward S-box, and a ChaCha20-IETF stream layer. The reconstructed payload is written to %TEMP%\pfNNNNN.dat and handed to powershell.exe via a two-tier loader whose in-source comments reference PowerShell process hollowing. Identifier and comment strings (Device Telemetry Aggregator, Verdant Signals Corp) act as a cover story, and the README explicitly claims the package has No installation scripts — directly contradicting the postinstall hook. The package ships no library code or legitimate functionality consistent with its stated purpose; its only install-time effect is to detonate the obfuscated Windows loader on the installer's machine.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020966",
            "import_time":  "2026-10-04T23:40:46.63193077Z",
            "modified_time":  "2026-10-04T23:27:22Z",
            "sha256":  "532663c4102d3cf7310e29ca1eb2b389c5c32c1e541da219b7c4364968f4e807",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / lite-mater

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "0d1ec0b5e54788a948a4a1c4129b1cf48c8138fc4b2a232dc68bd704f33eb747",
            "tlsh":  "34e0df13c9949f6310f8e7a1ad380612b6210f0f42728e0b70f7026c4ba66a7249fb6c"
        },
        {
            "path":  "4444.vbs",
            "sha256":  "89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a",
            "tlsh":  "daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "lite-mater-1.0.0.tgz",
            "hashes":  {
                "sha1":  "3953d8940adf83c9627ee13bd80665db0c566f2b",
                "sha512_sri":  "sha512-Tzn21DmSAH7qzWBS1SgqyKvYmZBCq+qwhp5toG5jB0dsRyt0+8JyxOJTirYkJodXkd1zwH3r6w+G67Rn9AtVwg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/lite-mater/MAL-2026-17511.json"