Logo
npm

lite-matterr@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17513

Ecosystem

npm

Summary

lite-matterr@1.0.0 declares a postinstall hook in package.json that runs wscript.exe 4444.vbs on npm install. The bundled 4444.vbs is a ~765KB heavily obfuscated VBScript containing layered decryption routines (XOR-masked AES S-boxes, a ChaCha20 stream layer, SHA-256 round constants XORed with 0x5A5A5A5A) and a ~600-entry base64 bundle that it concatenates and decrypts into a PowerShell loader. The decrypted loader is written to %TEMP%\pf<rand>.dat and executed via powershell.exe, with internal comments referencing process hollowing. The README falsely claims 'No network requests. No personal data storage. No installation scripts.', directly contradicting the declared postinstall. The package presents a 'Device Telemetry Aggregator' cover story while actually delivering a multi-stage Windows dropper that achieves code execution on any host that installs the package.

Source: amazon-inspector (cc9b5f5edaae9103fd26de7cb70e661d78d6948dc3c519fec6b4b62fd471fbfc)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.