MAL-2026-12501
Malicious code in william-data-formatter-x (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (df0b15d8ca8cdfac8baf861a2db501b3b52eb0e41fd44a6690c351bda8c90835) The package declares a preinstall script (node index.js) that, on Windows, spawns a hidden PowerShell window (-WindowStyle Hidden) to fetch https://files.catbox.moe/5khq55.zip, extract it to %TEMP%, and execute Verification_Tool.exe. The fetched binary is unpinned, unhashed, and hosted on an anonymous file-drop service unrelated to the package's stated purpose. The package name has a leading space (' william-data-formatter-x') and carries generic 'Internal sync utility' / 'IT Operations' metadata consistent with social-engineering framing. Installing this package on a Windows machine results in arbitrary attacker-controlled code executing on the installer's host at npm install time.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for william-data-formatter-x (npm). Pin to a known-safe version or switch to an alternative.