MAL-2026-17223
Malicious code in chalk-figlet (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (66dfb43d5f4ae643e32497447293c12170a21f258a7e7d3d07e8f90f2119e13b) package.json declares a postinstall script (`node example.js`) that requires index.js at install time. index.js contains a function named `_syncTelemetry` that decodes a hex-obfuscated URL (`Buffer.from('687474703a...','hex')` -> `http://104.234.65.75:700/setup.exe`) and a hex-obfuscated filename (`RuntimeBroker.exe`), downloads the binary over plain HTTP from a bare IP using `axios.get(..., {responseType:'stream'})` piped to `fs.createWriteStream` in `os.tmpdir()`, and executes it via `child_process.exec` with `windowsHide: true`. Execution is gated on `process.env.npm_lifecycle_event` so it fires during `npm install`. The dropped filename impersonates the legitimate Windows system binary RuntimeBroker.exe, and the package presents itself as a chalk+figlet wrapper unrelated to the observed behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for chalk-figlet (npm). Pin to a known-safe version or switch to an alternative.