{"id":"MAL-2026-17316","summary":"Malicious code in booking-eligibility (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2c93f5b06720659d8e0cc8efb7d6bd75f577605e84c27cfb600a795081c27654)\npackage.json declares a postinstall lifecycle hook `wscript.exe 4444.vbs` that runs Windows Script Host against a `.vbs` file on `npm install`. The referenced `4444.vbs` is not shipped in the tarball, so the hook either fails or (if the file is dropped by another mechanism or provided out-of-band) executes attacker-authored VBScript on the installer's machine at install time. The README explicitly claims 'No installation scripts', directly contradicting the manifest — a cover-story mismatch that misrepresents install-time behavior. The `4444` filename mirrors a well-known reverse-shell port convention. The package presents no legitimate functionality justifying WSH execution at install time.\n","modified":"2026-09-30T03:30:04.972903801Z","published":"2026-09-30T03:08:36Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020799","import_time":"2026-09-30T03:24:20.085213802Z","modified_time":"2026-09-30T03:08:36Z","sha256":"2c93f5b06720659d8e0cc8efb7d6bd75f577605e84c27cfb600a795081c27654"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/booking-eligibility/v/1.0.0"}],"affected":[{"package":{"name":"booking-eligibility","ecosystem":"npm","purl":"pkg:npm/booking-eligibility"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"f5e022238954ab6721f9e7b2ad354243b6690e0f02604c0730fb125c4b616b7209fb2d","path":"package.json","sha256":"3d0dc0d7ff9bb2ef305e4069ce709ee1223dd2a3b367145a5b3a6e3a1e39d787"},{"path":"readme.md","sha256":"11f2ec1d479385714632f19967af06a5273b66baf7ffab8c9f9e400092735026","tlsh":"3c3100444c23e37935b1e31bbc90b092e7f4915c0aa60c51b9aa835e1315f62fb7f84e"}],"package_integrity":[{"filename":"booking-eligibility-1.0.0.tgz","hashes":{"sha1":"5692583fd2e6a66ae9d9603c408cbc84ba5e0e1f","sha512_sri":"sha512-5BFi4KRLXKJVpAnBnlmLnf/B4OntDmcz/Bkuj+gN664faIwx5dQ0MnpwruwZCFWmdDbm76894GbOl2qNph/x4w=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/booking-eligibility/MAL-2026-17316.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}