VDB
Sign up
—

MAL-2026-17223

Malicious code in chalk-figlet (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (66dfb43d5f4ae643e32497447293c12170a21f258a7e7d3d07e8f90f2119e13b) package.json declares a postinstall script (`node example.js`) that requires index.js at install time. index.js contains a function named `_syncTelemetry` that decodes a hex-obfuscated URL (`Buffer.from('687474703a...','hex')` -> `http://104.234.65.75:700/setup.exe`) and a hex-obfuscated filename (`RuntimeBroker.exe`), downloads the binary over plain HTTP from a bare IP using `axios.get(..., {responseType:'stream'})` piped to `fs.createWriteStream` in `os.tmpdir()`, and executes it via `child_process.exec` with `windowsHide: true`. Execution is gated on `process.env.npm_lifecycle_event` so it fires during `npm install`. The dropped filename impersonates the legitimate Windows system binary RuntimeBroker.exe, and the package presents itself as a chalk+figlet wrapper unrelated to the observed behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/chalk-figlet

No fixed version published yet for chalk-figlet (npm). Pin to a known-safe version or switch to an alternative.

References