OpenSSF/OSV advisory MAL-2026-17624 confirms this npm version as malicious. documenclient@1.0.5 publishes an npm package whose only shipped content is a heavily obfuscated PowerShell script embedded in the README. The script hides its console window via ShowWindow(hWnd, 0), positions the window off-screen at (-32000, -32000) via SetWindowPos, sleeps a randomized interval, concatenates ~140 string fragments into a base64 blob, XOR-decodes it with key 89, and executes the resulting payload...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in documenclient (npm)
Details
documenclient@1.0.5 publishes an npm package whose only shipped content is a heavily obfuscated PowerShell script embedded in the README. The script hides its console window via ShowWindow(hWnd, 0), positions the window off-screen at (-32000, -32000) via SetWindowPos, sleeps a randomized interval, concatenates ~140 string fragments into a base64 blob, XOR-decodes it with key 89, and executes the resulting payload via reflective [ScriptBlock]::Create invocation assembled from char-code type and method names. The declared main (index.js) is absent and files is empty, so the artifact has no legitimate JavaScript functionality — the dropper script is the entire payload. Console hiding, off-screen window placement, randomized sleep jitter, dynamic type/method resolution, and XOR+base64 layering have no legitimate purpose in an npm README and are canonical dropper and anti-analysis techniques. The decoded payload is not inspectable from the obfuscated form shipped, so the final behavior on a Windows host executing the script is unknown but attacker-controlled.
## Source: ghsa-malware (fd77316cd00f6397a05779a443f939cd3a5e09efa8321c7d52bd4623ffe2855f) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Decision reason
No blocking static signals were detected.