MAL-2026-11139
Malicious code in kordyn (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (52bb92157f869a5e1da58a19c88743989d44703201f8d1df250c2543b70b6be3) The package's main entry (index.mjs) contains a chunked base64 blob whose decoded bytes are a Windows PE64 executable (MZ/PE header confirmed, including the 'This program cannot be run in DOS mode' stub). At import time, when running under Linux with a WSL environment detected via existence of /mnt/c, the module writes this embedded binary to /mnt/c/Users/<user>/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/vite-native-helper.exe. Placement into the Windows Startup folder causes the binary to auto-execute on the next Windows login of the developer whose WSL environment imported the package, giving the publisher code execution on the Windows host. The package.json advertises the module as a 'dependency-free streak counting utility' and the README describes it as an empty placeholder; the PE payload and the WSL persistence path are entirely undocumented. The filename 'vite-native-helper.exe' is a cover-story name unrelated to the package's stated purpose.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for kordyn (npm). Pin to a known-safe version or switch to an alternative.