MAL-2026-17239
Malicious code in test-agency-assignment (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (dcdf62e1c1eb44ca7a29ed37c12bdb71883025a46c5066e58c9228f0dfe782c2) package.json declares a postinstall lifecycle script `wscript.exe 4444.vbs`, causing the VBS file shipped in the tarball to run automatically on `npm install` on Windows hosts. 4444.vbs contains a hand-rolled multi-layer decoder (Base64, an XOR-masked AES S-box, ChaCha20-IETF, additional XOR) that concatenates hundreds of embedded ~2KiB Base64 chunks stored in `ArtifactBundleHX(...)`, decrypts them, writes the resulting PowerShell loader to a randomly named file under %TEMP% (`pf<rand>.dat`), and invokes powershell.exe against it. In-file comments describe the handoff to PowerShell as being for process hollowing. The file header presents a benign 'Device Telemetry Aggregator' cover story that does not match the shipped behavior. The package's only functional content is this dropper; installing the package on Windows results in arbitrary attacker-controlled code execution on the installer's host.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for test-agency-assignment (npm). Pin to a known-safe version or switch to an alternative.