MAL-2026-17523

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/studiocode_tools/MAL-2026-17523.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17523
Published
2026-10-04T23:25:54Z
Modified
2026-10-04T23:45:19Z
Summary
Malicious code in studiocode_tools (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (261d413c0847b530c9a452c209c25e0a7d9123f9b0f20b26d0afcc41a929c74a)

package.json declares a postinstall hook that runs wscript.exe 4444.vbs, auto-executing on npm install on Windows. The shipped 4444.vbs contains hand-rolled AES and ChaCha20 implementations with XOR-obfuscated S-boxes, SHA-256 round constants XORed with 0x5A5A5A5A, and hundreds of base64 ciphertext fragments (ArtifactBundleHX) that are reassembled and decrypted at runtime into a PowerShell loader. The script writes a payload file to %TEMP%\pfNNNNN.dat and invokes powershell.exe to perform process hollowing of the decrypted payload. The VBS carries cover-story branding as 'Verdant Signals Corp' / 'Device Telemetry Aggregator', and the README falsely states 'There are no installation scripts.' The multi-layer custom cryptography, false branding, and explicit README denial of install scripts are unambiguous indicators of hostile intent rather than legitimate functionality.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-020957",
            "import_time": "2026-10-04T23:40:45.795634608Z",
            "modified_time": "2026-10-04T23:25:54Z",
            "sha256": "261d413c0847b530c9a452c209c25e0a7d9123f9b0f20b26d0afcc41a929c74a",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / studiocode_tools

Package

Name
studiocode_tools
View open source insights on deps.dev
Purl
pkg:npm/studiocode_tools

Affected ranges

Affected versions

1.*
1.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "6e7bd5f933481ba3593774e51a414025cc44b8451262fa95b42eeebc77b3403b",
            "tlsh": "d5e02a238a549a2320f8e6a1b8380242b2600f0f02208c0b30fb021c4b6a6a3208ab6c"
        },
        {
            "path": "4444.vbs",
            "sha256": "89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a",
            "tlsh": "daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8"
        }
    ],
    "package_integrity": [
        {
            "filename": "studiocode_tools-1.0.1.tgz",
            "hashes": {
                "sha1": "99b228fe6b6982c0c248c0c87acf87ed51082fe5",
                "sha512_sri": "sha512-ea3cTKOFmmaMms8ZBFw55C9dp6PG9KZEhS+YRwsfRyd2KZYxbO//UUqKmT+HJ4VJJkD0FkcEKpCkInBYjWws1Q=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/studiocode_tools/MAL-2026-17523.json"