MAL-2026-12422Malicious code in quorvex (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
0.2.0 | unavailable | — | — | — |
0.2.1 | unavailable | — | — | — |
0.2.2 | unavailable | — | — | — |
| Ecosystem | Package | Version |
|---|---|---|
| npm | quorvex | 0.2.0 |
| npm | quorvex | 0.2.1 |
| npm | quorvex | 0.2.2 |
{"schema_version":"1.7.4","id":"MAL-2026-12422","published":"2026-08-05T12:25:31Z","modified":"2026-08-19T05:15:36.388370515Z","summary":"Malicious code in quorvex (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9127b24fd8619b810163b5b5714d580951a3a96cfa1b37e63a57ff3cc9c2cca5)\nquorvex@0.2.1 ships index.mjs as the package main, containing a base64-encoded Windows PE (~355KB) in a PAYLOAD constant. At import time on Windows hosts with more than 4GB of RAM, the code decodes the payload and writes it to %APPDATA%/Microsoft/Windows/Start Menu/Programs/Startup/vite-native-helper.exe, causing Windows to auto-execute the dropped binary at the next user logon. The README self-describes the package as a placeholder with 'nothing in here yet' while documenting deliberate anti-tree-shaking design ('index.mjs performs a real import-time assignment... that no bundler can prove is inert') to ensure the drop runs when the module is loaded. The vite-native-helper.exe filename and Vite-adjacent naming are a cover story; the memory-size gate is a sandbox-evasion check. Installing or importing this package on a Windows host results in an opaque attacker-controlled binary being placed in the user's Startup folder with logon-time persistence.\n","affected":[{"package":{"name":"quorvex","ecosystem":"npm"},"versions":["0.2.1","0.2.0","0.2.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.mjs","sha256":"3909d912213d84a44da8973384e853afcc6b3e7eff787400a0dac5068dcfbc9c","tlsh":"32746c72121bfcaa2aec2d80d0012d541e6d2e474624b165ebcbb0fa53ed557cd3d9bc"}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/quorvex/v/0.2.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/quorvex/v/0.2.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/quorvex/v/0.2.2"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014650","import_time":"2026-08-05T13:08:33.893348413Z","modified_time":"2026-08-05T12:25:31Z","sha256":"9127b24fd8619b810163b5b5714d580951a3a96cfa1b37e63a57ff3cc9c2cca5","source":"amazon-inspector","versions":["0.2.1"]},{"id":"IN-MAL-2026-014987","import_time":"2026-08-05T14:19:49.610566067Z","modified_time":"2026-08-05T13:38:22Z","sha256":"eb2613921a1fac2ba390b1d8e9795123284ad6a873544568b263e533c51ab152","source":"amazon-inspector","versions":["0.2.0"]},{"id":"IN-MAL-2026-018374","import_time":"2026-08-19T05:13:50.1783189Z","modified_time":"2026-08-19T05:12:03Z","sha256":"89b222a09b6a37394a00b225ea43eaae0bde251b6cbb7c0481784ca4333e7218","source":"amazon-inspector","versions":["0.2.2"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0