VYPR

npm · Malicious package advisory

Malware

lite-mater

GHSA-294m-x97c-p7xh

Malicious code in lite-mater (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (532663c4102d3cf7310e29ca1eb2b389c5c32c1e541da219b7c4364968f4e807)
package.json declares a postinstall lifecycle hook `wscript.exe 4444.vbs` that runs automatically on `npm install` on Windows hosts. The shipped 4444.vbs (~765 KB) is a multi-layer obfuscated loader: an embedded payload is stored as a large ArtifactBundleHX[] string array, Base64-decoded via MSXML DOM into a byte buffer, then decrypted through a custom XOR routine, an AES forward S-box, and a ChaCha20-IETF stream layer. The reconstructed payload is written to %TEMP%\pfNNNNN.dat and handed to powershell.exe via a two-tier loader whose in-source comments reference PowerShell process hollowing. Identifier and comment strings (`Device Telemetry Aggregator`, `Verdant Signals Corp`) act as a cover story, and the README explicitly claims the package has `No installation scripts` — directly contradicting the postinstall hook. The package ships no library code or legitimate functionality consistent with its stated purpose; its only install-time effect is to detonate the obfuscated Windows loader on the installer's machine.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/lite-mater/MAL-2026-17511.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/lite-mater/MAL-2026-17511.json
- https://www.npmjs.com/package/lite-mater/v/1.0.0
- https://github.com/advisories/GHSA-294m-x97c-p7xh

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.