Logo
npm

serpacksven2@1.0.0

Vulnerability report · Last retrieved from osv.dev October 6, 2026 at 2:31 PM UTC

Malicious

OSV ID

MAL-2026-17627

Ecosystem

npm

Summary

The tarball ships ten identical files with misleading extensions (1.png, client.doc, json.txt, server.doc, for.you.doc,.txt,.txt.1,.txt.2, and an extensionless 'client'), all sharing the same SHA-256 and all containing the same PowerShell script. The script hides its console window and moves it off-screen via SetWindowPos, concatenates roughly 150 base64 chunks, XOR-decodes them, and passes the resulting bytes to System.Reflection.Assembly.Load().Invoke — an in-memory.NET assembly loader characteristic of RAT/stealer stagers. The package has no index.js, no main entry, and no lifecycle scripts, so npm install and require() do not themselves run the loader; the package exists purely to deliver and disguise the staged PowerShell/.NET payload for later execution on the host.

Source: amazon-inspector (668c23a809283c521b8cee159ca2f57515729e664029b4fa63c1e1fbef1bd9fc)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.