-= Per source details. Do not edit below this line.=-
lite-matterr@1.0.0 declares a postinstall hook in package.json that runs wscript.exe 4444.vbs on npm install. The bundled 4444.vbs is a ~765KB heavily obfuscated VBScript containing layered decryption routines (XOR-masked AES S-boxes, a ChaCha20 stream layer, SHA-256 round constants XORed with 0x5A5A5A5A) and a ~600-entry base64 bundle that it concatenates and decrypts into a PowerShell loader. The decrypted loader is written to %TEMP%\pf.dat and executed via powershell.exe, with internal comments referencing process hollowing. The README falsely claims 'No network requests. No personal data storage. No installation scripts.', directly contradicting the declared postinstall. The package presents a 'Device Telemetry Aggregator' cover story while actually delivering a multi-stage Windows dropper that achieves code execution on any host that installs the package.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020967",
"import_time": "2026-10-04T23:40:46.76326531Z",
"modified_time": "2026-10-04T23:27:32Z",
"sha256": "cc9b5f5edaae9103fd26de7cb70e661d78d6948dc3c519fec6b4b62fd471fbfc",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "20fbf8bdcd999740087437745273ff632701edcff55dfe7fa794d81d9729b695",
"tlsh": "5ce0d817c9945e6350f9e7e5ad350612f6110f0f41714d0770f7025c4ba65a7149bb6d"
},
{
"path": "4444.vbs",
"sha256": "89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a",
"tlsh": "daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8"
},
{
"path": "readme.md",
"sha256": "11f2ec1d479385714632f19967af06a5273b66baf7ffab8c9f9e400092735026",
"tlsh": "3c3100444c23e37935b1e31bbc90b092e7f4915c0aa60c51b9aa835e1315f62fb7f84e"
}
],
"package_integrity": [
{
"filename": "lite-matterr-1.0.0.tgz",
"hashes": {
"sha1": "d4199699b18dbac9dcb66b036f42cc575dc1db65",
"sha512_sri": "sha512-8qat5nmaYOqHAU4YSDNf8t2v90x/Oj1dEQBg3KucUk/N1pKkiwEVo/Em75JJTbj0vdd977zWQmd+u0XjRolLZA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/lite-matterr/MAL-2026-17513.json"