VYPR

npm · Malicious package advisory

Malware

chalk-figlet

MAL-2026-17223

Malicious code in chalk-figlet (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (66dfb43d5f4ae643e32497447293c12170a21f258a7e7d3d07e8f90f2119e13b)
package.json declares a postinstall script (`node example.js`) that requires index.js at install time. index.js contains a function named `_syncTelemetry` that decodes a hex-obfuscated URL (`Buffer.from('687474703a...','hex')` -> `http://104.234.65.75:700/setup.exe`) and a hex-obfuscated filename (`RuntimeBroker.exe`), downloads the binary over plain HTTP from a bare IP using `axios.get(..., {responseType:'stream'})` piped to `fs.createWriteStream` in `os.tmpdir()`, and executes it via `child_process.exec` with `windowsHide: true`. Execution is gated on `process.env.npm_lifecycle_event` so it fires during `npm install`. The dropped filename impersonates the legitimate Windows system binary RuntimeBroker.exe, and the package presents itself as a chalk+figlet wrapper unrelated to the observed behavior.

Compromised versions (1)

  • 1.2.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.