Logo
npm

prettier-lint-lenz@2.6.4

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2026-3769

Ecosystem

npm

Summary

Package impersonates the popular prettier formatter — README and description are copied verbatim from the real Prettier project, but the package ships no formatter code. Instead, package.json declares "postinstall": "node index.mjs", which on Windows POSTs an install beacon to a hardcoded bare-IP C2 (http://204.10.194.64:5000/api/nonce), copies a bundled prettier-lint/ directory to %LOCALAPPDATA%\prettier-lint, and executes ctll.mjs from the deployed location. ctll.mjs writes a hidden VBScript runner and registers a Windows Scheduled Task named CdllProtect with a LogonTrigger (schtasks /Create /XML) that relaunches cdll.mjs via wscript.exe //nologo in a hidden window on every user logon, with 999 retries and no execution time limit. The deployed cdll.mjs polls the clipboard every ~250ms via powershell.exe Get-Clipboard -Raw and POSTs the raw clipboard text as JSON to the same hardcoded endpoint over plain HTTP on every change, exfiltrating passwords, 2FA codes, wallet addresses, and any copied text. All three components (install-time beacon, deployed worker, persistence) share the attacker-controlled endpoint 204.10.194.64:5000.

Source: amazon-inspector (28f7035dda69170600724a31f4b3543e02ac23c9153f3a62c35f2ee5264eef44)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.