{"id":"MAL-2026-17297","summary":"Malicious code in test-agency-assignment-02 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e9944ea8ca21c0670c4b718a12427e8ca7330571ef5a9198a60b05f75038fe73)\nThe tarball contains only package.json and 4444.vbs; the declared main entry (index.js) is absent. package.json defines a postinstall script `wscript.exe 4444.vbs`, so on `npm install` on Windows the VBScript executes automatically. 4444.vbs is heavily obfuscated (colon-delimited XOR-encoded CreateObject strings, embedded AES S-box and ChaCha20-IETF routines, and 600+ base64 fragments reconstructed at runtime) and presents cover strings identifying itself as `Device Telemetry Aggregator / Verdant Signals Corp.`. It reconstructs an encrypted payload, writes it to %TEMP% as a `pf*.dat` file, and invokes powershell.exe to perform process hollowing of the decoded loader. The package ships no library code — its only reachable behavior is the install-time dropper.\n","modified":"2026-09-29T23:30:05.063745822Z","published":"2026-09-29T23:05:45Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.5"],"id":"IN-MAL-2026-020692","import_time":"2026-09-29T23:17:35.356841763Z","modified_time":"2026-09-29T23:05:45Z","sha256":"e9944ea8ca21c0670c4b718a12427e8ca7330571ef5a9198a60b05f75038fe73","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/test-agency-assignment-02/v/1.0.5"}],"affected":[{"package":{"name":"test-agency-assignment-02","ecosystem":"npm","purl":"pkg:npm/test-agency-assignment-02"},"versions":["1.0.5"],"database_specific":{"indicators":{"package_integrity":[{"filename":"test-agency-assignment-02-1.0.5.tgz","hashes":{"sha512_sri":"sha512-pPlsB2BA0XQxORXa91N7mwr/AxfDsnPgfW/jddsANiFpHMcPNP+91cIojl+spJej3DfUTosTyNnV7sbB6hdKBA==","sha1":"02e66c207376d2e743cca7df0001733c0d24fb53"}}],"evidence_files":[{"tlsh":"01d0a7274945563369f446640935991ab5128f2f51314c0bb2f3651890e37b24889b06","path":"package.json","sha256":"ab92d275016fd5c87f726eaacc6d7a83ad87f62002a4cee7a07de79a8ee8ef5c"},{"path":"4444.vbs","sha256":"89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a","tlsh":"daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-agency-assignment-02/MAL-2026-17297.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}