Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16419 confirms this npm version as malicious. The package ships a Windows HTA/WSH loader that installs a remote MSI on the victim host under the control of a base URL supplied at runtime via window.__gsutBases. On execution it (1) disables Anti-Malware Scan Interface for Windows Script Host by writing HKCU\Software\Microsoft\Windows Script\Settings\AmsiEnable = 0 through both WScript.Shell.RegWrite and WMI StdRegProv.SetDWORDValue, with the value name...
This report applies to @gsutevil/hta-stage@1.62.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .