OpenSSF/OSV advisory MAL-2026-17523 confirms this npm version as malicious. package.json declares a postinstall hook that runs `wscript.exe 4444.vbs`, auto-executing on `npm install` on Windows. The shipped 4444.vbs contains hand-rolled AES and ChaCha20 implementations with XOR-obfuscated S-boxes, SHA-256 round constants XORed with 0x5A5A5A5A, and hundreds of base64 ciphertext fragments (`ArtifactBundleHX`) that are reassembled and decrypted at runtime into a PowerShell loader...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis report applies to studiocode_tools@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg