VYPR

npm · Malicious package advisory

Malware

lite-mater

MAL-2026-17511

Malicious code in lite-mater (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (532663c4102d3cf7310e29ca1eb2b389c5c32c1e541da219b7c4364968f4e807)
package.json declares a postinstall lifecycle hook `wscript.exe 4444.vbs` that runs automatically on `npm install` on Windows hosts. The shipped 4444.vbs (~765 KB) is a multi-layer obfuscated loader: an embedded payload is stored as a large ArtifactBundleHX[] string array, Base64-decoded via MSXML DOM into a byte buffer, then decrypted through a custom XOR routine, an AES forward S-box, and a ChaCha20-IETF stream layer. The reconstructed payload is written to %TEMP%\pfNNNNN.dat and handed to powershell.exe via a two-tier loader whose in-source comments reference PowerShell process hollowing. Identifier and comment strings (`Device Telemetry Aggregator`, `Verdant Signals Corp`) act as a cover story, and the README explicitly claims the package has `No installation scripts` — directly contradicting the postinstall hook. The package ships no library code or legitimate functionality consistent with its stated purpose; its only install-time effect is to detonate the obfuscated Windows loader on the installer's machine.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.