{"id":"MAL-2026-12422","summary":"Malicious code in quorvex (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9127b24fd8619b810163b5b5714d580951a3a96cfa1b37e63a57ff3cc9c2cca5)\nquorvex@0.2.1 ships index.mjs as the package main, containing a base64-encoded Windows PE (~355KB) in a PAYLOAD constant. At import time on Windows hosts with more than 4GB of RAM, the code decodes the payload and writes it to %APPDATA%/Microsoft/Windows/Start Menu/Programs/Startup/vite-native-helper.exe, causing Windows to auto-execute the dropped binary at the next user logon. The README self-describes the package as a placeholder with 'nothing in here yet' while documenting deliberate anti-tree-shaking design ('index.mjs performs a real import-time assignment... that no bundler can prove is inert') to ensure the drop runs when the module is loaded. The vite-native-helper.exe filename and Vite-adjacent naming are a cover story; the memory-size gate is a sandbox-evasion check. Installing or importing this package on a Windows host results in an opaque attacker-controlled binary being placed in the user's Startup folder with logon-time persistence.\n","modified":"2026-08-05T14:37:18.121772722Z","published":"2026-08-05T12:25:31Z","database_specific":{"malicious-packages-origins":[{"sha256":"9127b24fd8619b810163b5b5714d580951a3a96cfa1b37e63a57ff3cc9c2cca5","source":"amazon-inspector","versions":["0.2.1"],"id":"IN-MAL-2026-014650","import_time":"2026-08-05T13:08:33.893348413Z","modified_time":"2026-08-05T12:25:31Z"},{"versions":["0.2.0"],"id":"IN-MAL-2026-014987","import_time":"2026-08-05T14:19:49.610566067Z","modified_time":"2026-08-05T13:38:22Z","sha256":"eb2613921a1fac2ba390b1d8e9795123284ad6a873544568b263e533c51ab152","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/quorvex/v/0.2.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/quorvex/v/0.2.0"}],"affected":[{"package":{"name":"quorvex","ecosystem":"npm","purl":"pkg:npm/quorvex"},"versions":["0.2.1","0.2.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"32746c72121bfcaa2aec2d80d0012d541e6d2e474624b165ebcbb0fa53ed557cd3d9bc","path":"index.mjs","sha256":"3909d912213d84a44da8973384e853afcc6b3e7eff787400a0dac5068dcfbc9c"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/quorvex/MAL-2026-12422.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}