{"id":"MAL-2026-17523","summary":"Malicious code in studiocode_tools (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (261d413c0847b530c9a452c209c25e0a7d9123f9b0f20b26d0afcc41a929c74a)\npackage.json declares a postinstall hook that runs `wscript.exe 4444.vbs`, auto-executing on `npm install` on Windows. The shipped 4444.vbs contains hand-rolled AES and ChaCha20 implementations with XOR-obfuscated S-boxes, SHA-256 round constants XORed with 0x5A5A5A5A, and hundreds of base64 ciphertext fragments (`ArtifactBundleHX`) that are reassembled and decrypted at runtime into a PowerShell loader. The script writes a payload file to `%TEMP%\\pfNNNNN.dat` and invokes `powershell.exe` to perform process hollowing of the decrypted payload. The VBS carries cover-story branding as 'Verdant Signals Corp' / 'Device Telemetry Aggregator', and the README falsely states 'There are no installation scripts.' The multi-layer custom cryptography, false branding, and explicit README denial of install scripts are unambiguous indicators of hostile intent rather than legitimate functionality.\n","modified":"2026-10-04T23:45:19.409187930Z","published":"2026-10-04T23:25:54Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-020957","import_time":"2026-10-04T23:40:45.795634608Z","modified_time":"2026-10-04T23:25:54Z","sha256":"261d413c0847b530c9a452c209c25e0a7d9123f9b0f20b26d0afcc41a929c74a","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/studiocode_tools/v/1.0.1"}],"affected":[{"package":{"name":"studiocode_tools","ecosystem":"npm","purl":"pkg:npm/studiocode_tools"},"versions":["1.0.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"6e7bd5f933481ba3593774e51a414025cc44b8451262fa95b42eeebc77b3403b","tlsh":"d5e02a238a549a2320f8e6a1b8380242b2600f0f02208c0b30fb021c4b6a6a3208ab6c"},{"tlsh":"daf4f034658a68abb63bcafeace6c72935147c053040606c35deb6581bfdcd15bda0f8","path":"4444.vbs","sha256":"89a31ec0719b2137938c892385823ffb993d2d903e1fdfe17b246ba88531609a"}],"package_integrity":[{"hashes":{"sha1":"99b228fe6b6982c0c248c0c87acf87ed51082fe5","sha512_sri":"sha512-ea3cTKOFmmaMms8ZBFw55C9dp6PG9KZEhS+YRwsfRyd2KZYxbO//UUqKmT+HJ4VJJkD0FkcEKpCkInBYjWws1Q=="},"filename":"studiocode_tools-1.0.1.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/studiocode_tools/MAL-2026-17523.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}