OpenSSF/OSV advisory MAL-2026-17624 confirms this npm version as malicious. documenclient@1.0.5 publishes an npm package whose only shipped content is a heavily obfuscated PowerShell script embedded in the README. The script hides its console window via ShowWindow(hWnd, 0), positions the window off-screen at (-32000, -32000) via SetWindowPos, sleeps a randomized interval, concatenates ~140 string fragments into a base64 blob, XOR-decodes it with key 89, and executes the resulting payload...
This report applies to documenclient@1.0.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.