-= Per source details. Do not edit below this line.=-
package.json declares a postinstall hook that runs wscript.exe 4444.vbs, auto-executing on npm install on Windows. The shipped 4444.vbs contains hand-rolled AES and ChaCha20 implementations with XOR-obfuscated S-boxes, SHA-256 round constants XORed with 0x5A5A5A5A, and hundreds of base64 ciphertext fragments (ArtifactBundleHX) that are reassembled and decrypted at runtime into a PowerShell loader. The script writes a payload file to %TEMP%\pfNNNNN.dat and invokes powershell.exe to perform process hollowing of the decrypted payload. The VBS carries cover-story branding as 'Verdant Signals Corp' / 'Device Telemetry Aggregator', and the README falsely states 'There are no installation scripts.' The multi-layer custom cryptography, false branding, and explicit README denial of install scripts are unambiguous indicators of hostile intent rather than legitimate functionality.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020957",
"import_time": "2026-10-04T23:40:45.795634608Z",
"modified_time": "2026-10-04T23:25:54Z",
"sha256": "261d413c0847b530c9a452c209c25e0a7d9123f9b0f20b26d0afcc41a929c74a",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "6e7bd5f933481ba3593774e51a414025cc44b8451262fa95b42eeebc77b3403b",
"tlsh": "d5e02a238a549a2320f8e6a1b8380242b2600f0f02208c0b30fb021c4b6a6a3208ab6c"
},
{
"path": "4444.vbs",
"sha256": "89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a",
"tlsh": "daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8"
}
],
"package_integrity": [
{
"filename": "studiocode_tools-1.0.1.tgz",
"hashes": {
"sha1": "99b228fe6b6982c0c248c0c87acf87ed51082fe5",
"sha512_sri": "sha512-ea3cTKOFmmaMms8ZBFw55C9dp6PG9KZEhS+YRwsfRyd2KZYxbO//UUqKmT+HJ4VJJkD0FkcEKpCkInBYjWws1Q=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/studiocode_tools/MAL-2026-17523.json"