npm · Malicious package advisory
Malwarelite-matterr
GHSA-6p6v-j47j-wgcr
Malicious code in lite-matterr (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (cc9b5f5edaae9103fd26de7cb70e661d78d6948dc3c519fec6b4b62fd471fbfc) [email protected] declares a postinstall hook in package.json that runs `wscript.exe 4444.vbs` on `npm install`. The bundled 4444.vbs is a ~765KB heavily obfuscated VBScript containing layered decryption routines (XOR-masked AES S-boxes, a ChaCha20 stream layer, SHA-256 round constants XORed with 0x5A5A5A5A) and a ~600-entry base64 bundle that it concatenates and decrypts into a PowerShell loader. The decrypted loader is written to %TEMP%\pf<rand>.dat and executed via powershell.exe, with internal comments referencing process hollowing. The README falsely claims 'No network requests. No personal data storage. No installation scripts.', directly contradicting the declared postinstall. The package presents a 'Device Telemetry Aggregator' cover story while actually delivering a multi-stage Windows dropper that achieves code execution on any host that installs the package. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/lite-matterr/MAL-2026-17513.json)) **References:** - https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/lite-matterr/MAL-2026-17513.json - https://www.npmjs.com/package/lite-matterr/v/1.0.0 - https://github.com/advisories/GHSA-6p6v-j47j-wgcr
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.