{"id":"MAL-2026-17511","summary":"Malicious code in lite-mater (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (532663c4102d3cf7310e29ca1eb2b389c5c32c1e541da219b7c4364968f4e807)\npackage.json declares a postinstall lifecycle hook `wscript.exe 4444.vbs` that runs automatically on `npm install` on Windows hosts. The shipped 4444.vbs (~765 KB) is a multi-layer obfuscated loader: an embedded payload is stored as a large ArtifactBundleHX[] string array, Base64-decoded via MSXML DOM into a byte buffer, then decrypted through a custom XOR routine, an AES forward S-box, and a ChaCha20-IETF stream layer. The reconstructed payload is written to %TEMP%\\pfNNNNN.dat and handed to powershell.exe via a two-tier loader whose in-source comments reference PowerShell process hollowing. Identifier and comment strings (`Device Telemetry Aggregator`, `Verdant Signals Corp`) act as a cover story, and the README explicitly claims the package has `No installation scripts` — directly contradicting the postinstall hook. The package ships no library code or legitimate functionality consistent with its stated purpose; its only install-time effect is to detonate the obfuscated Windows loader on the installer's machine.\n","modified":"2026-10-04T23:45:18.917352706Z","published":"2026-10-04T23:27:22Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-020966","import_time":"2026-10-04T23:40:46.63193077Z","modified_time":"2026-10-04T23:27:22Z","sha256":"532663c4102d3cf7310e29ca1eb2b389c5c32c1e541da219b7c4364968f4e807","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/lite-mater/v/1.0.0"}],"affected":[{"package":{"name":"lite-mater","ecosystem":"npm","purl":"pkg:npm/lite-mater"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"0d1ec0b5e54788a948a4a1c4129b1cf48c8138fc4b2a232dc68bd704f33eb747","tlsh":"34e0df13c9949f6310f8e7a1ad380612b6210f0f42728e0b70f7026c4ba66a7249fb6c","path":"package.json"},{"tlsh":"daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8","path":"4444.vbs","sha256":"89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a"}],"package_integrity":[{"filename":"lite-mater-1.0.0.tgz","hashes":{"sha1":"3953d8940adf83c9627ee13bd80665db0c566f2b","sha512_sri":"sha512-Tzn21DmSAH7qzWBS1SgqyKvYmZBCq+qwhp5toG5jB0dsRyt0+8JyxOJTirYkJodXkd1zwH3r6w+G67Rn9AtVwg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/lite-mater/MAL-2026-17511.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}