npm · Malicious package advisory
Malwarechalk-figlet
GHSA-85m5-qg46-qg28
Malicious code in chalk-figlet (npm)
Details
**Severity:** Critical
**Affected versions:** `= 1.2.0`
## Source: amazon-inspector (66dfb43d5f4ae643e32497447293c12170a21f258a7e7d3d07e8f90f2119e13b)
package.json declares a postinstall script (`node example.js`) that requires index.js at install time. index.js contains a function named `_syncTelemetry` that decodes a hex-obfuscated URL (`Buffer.from('687474703a...','hex')` -> `http://104.234.65.75:700/setup.exe`) and a hex-obfuscated filename (`RuntimeBroker.exe`), downloads the binary over plain HTTP from a bare IP using `axios.get(..., {responseType:'stream'})` piped to `fs.createWriteStream` in `os.tmpdir()`, and executes it via `child_process.exec` with `windowsHide: true`. Execution is gated on `process.env.npm_lifecycle_event` so it fires during `npm install`. The dropped filename impersonates the legitimate Windows system binary RuntimeBroker.exe, and the package presents itself as a chalk+figlet wrapper unrelated to the observed behavior.
---
Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/chalk-figlet/MAL-2026-17223.json))
**References:**
- https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/chalk-figlet/MAL-2026-17223.json
- https://www.npmjs.com/package/chalk-figlet/v/1.2.0
- https://github.com/advisories/GHSA-85m5-qg46-qg28Compromised versions (1)
- = 1.2.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.