VDB

GCVE-110-OSM-2026-12667

GCVE-110-OSM-2026-12667
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 28, 2026
package.json declares a postinstall lifecycle script `wscript.exe 4444.vbs`, causing the VBS file shipped in the tarball to run automatically on `npm install` on Windows hosts. 4444.vbs contains a hand-rolled multi-layer decoder (Base64, an XOR-masked AES S-box, ChaCha20-IETF, additional XOR) that concatenates hundreds of embedded ~2KiB Base64 chunks stored in `ArtifactBundleHX(...)`, decrypts them, writes the resulting PowerShell loader to a randomly named file under %TEMP% (`pf<rand>.dat`), and invokes powershell.exe against it. In-file comments describe the handoff to PowerShell as being for process hollowing. The file header presents a benign 'Device Telemetry Aggregator' cover story that does not match the shipped behavior. The package's only functional content is this dropper; installing the package on Windows results in arbitrary attacker-controlled code execution on the installer's host. ENTRY - Postinstall Script in package.json: ""postinstall": "wscript.exe 4444.vbs"" ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowntest-agency-assignmentall (affected)—

References

advisory
vendor

Browse GCVE Records

3,105 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›