serpacksven1@1.0.6
Vulnerability report · Last retrieved from osv.dev October 6, 2026 at 2:31 PM UTC
OSV ID
MAL-2026-17626
Ecosystem
npm
Summary
The tarball ships no JavaScript — the declared main: index.js is absent — and contains only 10 byte-identical copies of a PowerShell dropper under misleading extensions (1.png, client.doc, client.doc.1, json.txt, extensionless client, all sha256 e9dff494...). The script hides the console window via Win32 APIs, concatenates ~150 base64 chunks, XOR-decodes them with single-byte key 89, reflectively resolves [System.Reflection.Assembly].Load through char-code-obfuscated type strings, and invokes the decoded in-memory.NET assembly. The package has no lifecycle scripts and no importable surface, so npm install alone does not execute the payload; the harm fires when a second-stage tool or downstream workflow sources any of the disguised files (e.g. powershell -File client.doc), delivering full-host code execution of an attacker-controlled.NET assembly on Windows. The multi-extension disguise, byte-identical duplication, and absence of any legitimate package content show this is a payload-staging artifact published to npm rather than a software package.
Source: amazon-inspector (20d4a6a2715973b427bb0aa2b7a493ca711b7f16b5f47f90062edf790e0186a6)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.