studiocode_tools@1.0.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17523
Ecosystem
npm
Summary
package.json declares a postinstall hook that runs wscript.exe 4444.vbs, auto-executing on npm install on Windows. The shipped 4444.vbs contains hand-rolled AES and ChaCha20 implementations with XOR-obfuscated S-boxes, SHA-256 round constants XORed with 0x5A5A5A5A, and hundreds of base64 ciphertext fragments (ArtifactBundleHX) that are reassembled and decrypted at runtime into a PowerShell loader. The script writes a payload file to %TEMP%\pfNNNNN.dat and invokes powershell.exe to perform process hollowing of the decrypted payload. The VBS carries cover-story branding as 'Verdant Signals Corp' / 'Device Telemetry Aggregator', and the README falsely states 'There are no installation scripts.' The multi-layer custom cryptography, false branding, and explicit README denial of install scripts are unambiguous indicators of hostile intent rather than legitimate functionality.
Source: amazon-inspector (261d413c0847b530c9a452c209c25e0a7d9123f9b0f20b26d0afcc41a929c74a)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.