OpenSSF/OSV advisory MAL-2026-17317 confirms this npm version as malicious. The package's package.json declares a postinstall hook `wscript.exe 4444.vbs` that fires automatically on `npm install`. The bundled 4444.vbs contains hand-rolled AES-128 (with XOR-masked forward/inverse S-boxes), a ChaCha20-IETF stream, XOR-masked SHA-256 round constants, a Base64 decoder via MSXML DOM, and a chunked Base64 ciphertext blob (ArtifactBundleHX, ~665 chunks)...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis report applies to booking-tasks@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg