Logo
npm

documenclient@1.0.5

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:42 AM UTC

Malicious

OSV ID

MAL-2026-17624

Ecosystem

npm

Summary

documenclient@1.0.5 publishes an npm package whose only shipped content is a heavily obfuscated PowerShell script embedded in the README. The script hides its console window via ShowWindow(hWnd, 0), positions the window off-screen at (-32000, -32000) via SetWindowPos, sleeps a randomized interval, concatenates ~140 string fragments into a base64 blob, XOR-decodes it with key 89, and executes the resulting payload via reflective [ScriptBlock]::Create invocation assembled from char-code type and method names. The declared main (index.js) is absent and files is empty, so the artifact has no legitimate JavaScript functionality — the dropper script is the entire payload. Console hiding, off-screen window placement, randomized sleep jitter, dynamic type/method resolution, and XOR+base64 layering have no legitimate purpose in an npm README and are canonical dropper and anti-analysis techniques. The decoded payload is not inspectable from the obfuscated form shipped, so the final behavior on a Windows host executing the script is unknown but attacker-controlled.

Source: amazon-inspector (ffd20318a8d48dc20fee95097373ebd1039481031985164a651d2b68d366565a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.