test-agency-assignment@1.0.2
Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 11:09 PM UTC
OSV ID
MAL-2026-17239
Ecosystem
npm
Summary
package.json declares a postinstall lifecycle script wscript.exe 4444.vbs, causing the VBS file shipped in the tarball to run automatically on npm install on Windows hosts. 4444.vbs contains a hand-rolled multi-layer decoder (Base64, an XOR-masked AES S-box, ChaCha20-IETF, additional XOR) that concatenates hundreds of embedded ~2KiB Base64 chunks stored in ArtifactBundleHX(...), decrypts them, writes the resulting PowerShell loader to a randomly named file under %TEMP% (pf<rand>.dat), and invokes powershell.exe against it. In-file comments describe the handoff to PowerShell as being for process hollowing. The file header presents a benign 'Device Telemetry Aggregator' cover story that does not match the shipped behavior. The package's only functional content is this dropper; installing the package on Windows results in arbitrary attacker-controlled code execution on the installer's host.
Source: amazon-inspector (dcdf62e1c1eb44ca7a29ed37c12bdb71883025a46c5066e58c9228f0dfe782c2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.