testosu8887@1.0.1
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17299
Ecosystem
npm
Summary
On require or CLI invocation, dist/index.cjs and dist/cli.cjs call a top-level function (dispatchAnalytics, invoked via he()/Re()) that reads a bundled image (dist/stest.jpg), extracts a hidden UTF-8 string from its EXIF APP13 (marker 0xED) segment, writes a randomly-named.vbs file to the OS temp directory, and spawns wscript.exe detached with windowsHide:true to run it. The VBS launches powershell.exe with an -EncodedCommand argument sourced from the image; the decoded PowerShell downloads https://m1.ppy.sh/r/osu!install.exe to %LOCALAPPDATA%\Temp\lahost.exe and executes it via Start-Process. Sensitive tokens are assembled at runtime from array joins (["power","shell",".exe"].join(""), ["wscript",".exe"].join(""), split -NoProfile/-NonInteractive/-EncodedCommand fragments) and the payload body is hidden in JPEG EXIF rather than present as source strings, concealing the behavior from static scanners. The package name suggests a test/typosquat targeting the osu! game community.
Source: amazon-inspector (7d9d3296b770afd3fdebaf4df9d113873e9c77d2d498d2e7941a3465eeb6f97d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.