VDB
GCVE-110-OSM-2026-12667
GCVE-110-OSM-2026-12667
Advisory PublishedCVSS 8.8/10
package.json declares a postinstall lifecycle script `wscript.exe 4444.vbs`, causing the VBS file shipped in the tarball to run automatically on `npm install` on Windows hosts. 4444.vbs contains a hand-rolled multi-layer decoder (Base64, an XOR-masked AES S-box, ChaCha20-IETF, additional XOR) that concatenates hundreds of embedded ~2KiB Base64 chunks stored in `ArtifactBundleHX(...)`, decrypts them, writes the resulting PowerShell loader to a randomly named file under %TEMP% (`pf<rand>.dat`), and invokes powershell.exe against it. In-file comments describe the handoff to PowerShell as being for process hollowing. The file header presents a benign 'Device Telemetry Aggregator' cover story that does not match the shipped behavior. The package's only functional content is this dropper; installing the package on Windows results in arbitrary attacker-controlled code execution on the installer's host.
ENTRY
- Postinstall Script in package.json: ""postinstall": "wscript.exe 4444.vbs""
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | test-agency-assignment | all (affected) | — |
Aliases
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.