Logo
npm

chalk-figlet@1.2.0

Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 8:08 PM UTC

Malicious

OSV ID

MAL-2026-17223

Ecosystem

npm

Summary

package.json declares a postinstall script (node example.js) that requires index.js at install time. index.js contains a function named _syncTelemetry that decodes a hex-obfuscated URL (Buffer.from('687474703a...','hex') -> http://104.234.65.75:700/setup.exe) and a hex-obfuscated filename (RuntimeBroker.exe), downloads the binary over plain HTTP from a bare IP using axios.get(..., {responseType:'stream'}) piped to fs.createWriteStream in os.tmpdir(), and executes it via child_process.exec with windowsHide: true. Execution is gated on process.env.npm_lifecycle_event so it fires during npm install. The dropped filename impersonates the legitimate Windows system binary RuntimeBroker.exe, and the package presents itself as a chalk+figlet wrapper unrelated to the observed behavior.

Source: amazon-inspector (66dfb43d5f4ae643e32497447293c12170a21f258a7e7d3d07e8f90f2119e13b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.