MAL-2026-17522

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/studiocode_eligibility/MAL-2026-17522.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17522
Published
2026-10-04T23:25:45Z
Modified
2026-10-04T23:45:20Z
Summary
Malicious code in studiocode_eligibility (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a49b1af8bbf0463bb38d3049e59c28b0dcc8d2e3e5ef54611b4e77bddfdd36dc)

package.json declares a postinstall hook wscript.exe 4444.vbs that automatically executes a 765KB VBScript shipped in the tarball on Windows installers. The VBS contains multi-layer obfuscation (XOR-decoded AES S-boxes, SHA-256 constants, a ChaCha20 stream layer, and a large Base64 'ArtifactBundleHX' blob) that decrypts a PowerShell loader, writes it to %TEMP%\pf#####.dat, and invokes it via powershell.exe using process-hollowing-style techniques. The library source (src/index.js) is a small Zod-based email-domain eligibility checker that is unrelated to the VBS payload and serves as cover. The README explicitly claims 'Checks run locally, without network requests' and 'There are no installation scripts', directly contradicting the declared postinstall hook and shipped dropper. Running npm install studiocode_eligibility on Windows grants the package author arbitrary code execution on the installer's machine.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-020956",
            "import_time": "2026-10-04T23:40:45.696215061Z",
            "modified_time": "2026-10-04T23:25:45Z",
            "sha256": "a49b1af8bbf0463bb38d3049e59c28b0dcc8d2e3e5ef54611b4e77bddfdd36dc",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / studiocode_eligibility

Package

Name
studiocode_eligibility
View open source insights on deps.dev
Purl
pkg:npm/studiocode_eligibility

Affected ranges

Affected versions

1.*
1.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "a1fbddc50c680ba1998faca6166d379678f6ddbb1ab2773cc9684f995130e1a1",
            "tlsh": "2be0221389449a2320f9e6a1b8340252b2600f0f02204c0b30f7121c4b655b3208ab6d"
        },
        {
            "path": "4444.vbs",
            "sha256": "89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a",
            "tlsh": "daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8"
        },
        {
            "path": "readme.md",
            "sha256": "6a2f6de622c22f0d8a82d5c08d4d5eb90b3da7e7f526caa25886e374a610e557",
            "tlsh": "853132811967f2b229fa93dcbc42d146b7708020171b1ca1f0ae824d274ab42fb3f15d"
        }
    ],
    "package_integrity": [
        {
            "filename": "studiocode_eligibility-1.0.1.tgz",
            "hashes": {
                "sha1": "4a352520b827ea7892b7ce2492710503e05e98d5",
                "sha512_sri": "sha512-KMVaMdnIa9JB8fpbNX013lIYMnmDn2W7bMrtTGSjs3w6mL6K+MuXofctPglvgRukpizprSt1ljk8RZGWljaARg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/studiocode_eligibility/MAL-2026-17522.json"