OpenSSF/OSV advisory MAL-2026-17522 confirms this npm version as malicious. package.json declares a postinstall hook `wscript.exe 4444.vbs` that automatically executes a 765KB VBScript shipped in the tarball on Windows installers. The VBS contains multi-layer obfuscation (XOR-decoded AES S-boxes, SHA-256 constants, a ChaCha20 stream layer, and a large Base64 'ArtifactBundleHX' blob) that decrypts a PowerShell loader, writes it to %TEMP%\pf#####.dat, and invokes it via powershell.exe using...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis report applies to studiocode_eligibility@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg