Logo
npm

test-agency-assignment-02@1.0.5

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17297

Ecosystem

npm

Summary

The tarball contains only package.json and 4444.vbs; the declared main entry (index.js) is absent. package.json defines a postinstall script wscript.exe 4444.vbs, so on npm install on Windows the VBScript executes automatically. 4444.vbs is heavily obfuscated (colon-delimited XOR-encoded CreateObject strings, embedded AES S-box and ChaCha20-IETF routines, and 600+ base64 fragments reconstructed at runtime) and presents cover strings identifying itself as Device Telemetry Aggregator / Verdant Signals Corp.. It reconstructs an encrypted payload, writes it to %TEMP% as a pf*.dat file, and invokes powershell.exe to perform process hollowing of the decoded loader. The package ships no library code — its only reachable behavior is the install-time dropper.

Source: amazon-inspector (e9944ea8ca21c0670c4b718a12427e8ca7330571ef5a9198a60b05f75038fe73)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.