VYPR

npm · Malicious package advisory

Malware

studiocode_eligibility

GHSA-chvh-489x-9963

Malicious code in studiocode_eligibility (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.1`

## Source: amazon-inspector (a49b1af8bbf0463bb38d3049e59c28b0dcc8d2e3e5ef54611b4e77bddfdd36dc)
package.json declares a postinstall hook `wscript.exe 4444.vbs` that automatically executes a 765KB VBScript shipped in the tarball on Windows installers. The VBS contains multi-layer obfuscation (XOR-decoded AES S-boxes, SHA-256 constants, a ChaCha20 stream layer, and a large Base64 'ArtifactBundleHX' blob) that decrypts a PowerShell loader, writes it to %TEMP%\pf#####.dat, and invokes it via powershell.exe using process-hollowing-style techniques. The library source (src/index.js) is a small Zod-based email-domain eligibility checker that is unrelated to the VBS payload and serves as cover. The README explicitly claims 'Checks run locally, without network requests' and 'There are no installation scripts', directly contradicting the declared postinstall hook and shipped dropper. Running `npm install studiocode_eligibility` on Windows grants the package author arbitrary code execution on the installer's machine.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/studiocode_eligibility/MAL-2026-17522.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/studiocode_eligibility/MAL-2026-17522.json
- https://www.npmjs.com/package/studiocode_eligibility/v/1.0.1
- https://github.com/advisories/GHSA-chvh-489x-9963

Compromised versions (1)

  • = 1.0.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.