npm · Malicious package advisory
Malwarelite-mater
MAL-2026-17511
Malicious code in lite-mater (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (532663c4102d3cf7310e29ca1eb2b389c5c32c1e541da219b7c4364968f4e807) package.json declares a postinstall lifecycle hook `wscript.exe 4444.vbs` that runs automatically on `npm install` on Windows hosts. The shipped 4444.vbs (~765 KB) is a multi-layer obfuscated loader: an embedded payload is stored as a large ArtifactBundleHX[] string array, Base64-decoded via MSXML DOM into a byte buffer, then decrypted through a custom XOR routine, an AES forward S-box, and a ChaCha20-IETF stream layer. The reconstructed payload is written to %TEMP%\pfNNNNN.dat and handed to powershell.exe via a two-tier loader whose in-source comments reference PowerShell process hollowing. Identifier and comment strings (`Device Telemetry Aggregator`, `Verdant Signals Corp`) act as a cover story, and the README explicitly claims the package has `No installation scripts` — directly contradicting the postinstall hook. The package ships no library code or legitimate functionality consistent with its stated purpose; its only install-time effect is to detonate the obfuscated Windows loader on the installer's machine.
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.