Logo
npm

figlet-chalk-render@1.2.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC

Malicious

OSV ID

MAL-2026-17226

Ecosystem

npm

Summary

On every require('figlet-chalk-render'), a top-level IIFE queries https://registry.npmjs.org/figlet-chalk-render/latest and, if a newer version exists, spawns npm install figlet-chalk-render@<latest> with cwd set to path.join(__dirname, '..', '..') (the consumer project's root) and stdio ignored. The https, child_process, and path core-module names are loaded via hex-escaped string literals ('\x63\x68\x69\x6c\x64\x5f\x70\x72\x6f\x63\x65\x73\x73', etc.) rather than plain identifiers, deliberately hiding the sensitive requires backing the auto-update. The behavior is undocumented in the README. Every consumer that imports the module receives whatever the latest published version happens to be at that moment, executed with the installer's npm privileges and lifecycle scripts, giving anyone who later controls this package name a silent code-execution channel into every installer's project tree. The hex-obfuscation of the module names is anti-evasion and rebuts a benign-self-update reading: legitimate insecure-update code does not disguise require('child_process').

Source: amazon-inspector (d5ccd0a988525d8128b520a46c4271e26ae5fe2f99accf28f37d4c7370b66de4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.