{"id":"MAL-2026-17239","summary":"Malicious code in test-agency-assignment (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dcdf62e1c1eb44ca7a29ed37c12bdb71883025a46c5066e58c9228f0dfe782c2)\npackage.json declares a postinstall lifecycle script `wscript.exe 4444.vbs`, causing the VBS file shipped in the tarball to run automatically on `npm install` on Windows hosts. 4444.vbs contains a hand-rolled multi-layer decoder (Base64, an XOR-masked AES S-box, ChaCha20-IETF, additional XOR) that concatenates hundreds of embedded ~2KiB Base64 chunks stored in `ArtifactBundleHX(...)`, decrypts them, writes the resulting PowerShell loader to a randomly named file under %TEMP% (`pf\u003crand\u003e.dat`), and invokes powershell.exe against it. In-file comments describe the handoff to PowerShell as being for process hollowing. The file header presents a benign 'Device Telemetry Aggregator' cover story that does not match the shipped behavior. The package's only functional content is this dropper; installing the package on Windows results in arbitrary attacker-controlled code execution on the installer's host.\n","modified":"2026-09-28T22:30:06.805587707Z","published":"2026-09-28T22:03:04Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-020611","import_time":"2026-09-28T22:18:22.479197758Z","modified_time":"2026-09-28T22:03:04Z","sha256":"dcdf62e1c1eb44ca7a29ed37c12bdb71883025a46c5066e58c9228f0dfe782c2"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/test-agency-assignment/v/1.0.2"}],"affected":[{"package":{"name":"test-agency-assignment","ecosystem":"npm","purl":"pkg:npm/test-agency-assignment"},"versions":["1.0.2"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"test-agency-assignment-1.0.2.tgz","hashes":{"sha1":"75c09d06aa8e36ddb9c4fa79ae9359625bf338b9","sha512_sri":"sha512-QFNwa4A6D07b6XzW/pZORsllAx2DWxB0CtbT8z32V/4gghmBVQQaWJ8Ik92AUwhsI+3JLYYI3R2+9Ava6LSRxA=="}}],"evidence_files":[{"sha256":"60b89a83cb5dfa6b32a01f4332fed1392196cc0d4b668322e8badcd2142d36e6","tlsh":"90d0a7274945963329f4475409718416b5128f1f10314c0bb2f3651890e36b24889b06","path":"package.json"},{"tlsh":"daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8","path":"4444.vbs","sha256":"89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-agency-assignment/MAL-2026-17239.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}