Malicious code in caldora (npm)
The npm package caldora version 1.0.0 contains malicious code that executes on import when run in a Linux environment with the Windows Subsystem for Linux (WSL) present and NODE_ENV not set to 'production'. It downloads a binary from a third-party file host and writes it as 'vite-native-helper.exe' into the Windows user's Startup folder, enabling persistent execution on the Windows host at next login. The payload is obfuscated by splitting the URL into parts and is dormant in typical developer or CI environments, targeting WSL developer hosts specifically. The package's declared functionality does not require this native helper, indicating malicious intent.
AI Analysis
Technical Summary
The caldora npm package version 1.0.0 runs a top-level asynchronous routine on import that, under specific conditions (Linux with /mnt/c present indicating WSL, and NODE_ENV not 'production'), constructs a URL from split strings to download a binary file named 'vite-native-helper.exe' from a third-party host (f004.backblazeb2.com). This binary is then written into the Windows Startup folder of the host user, ensuring it runs automatically on the next Windows login. This behavior establishes persistent code execution on the Windows host originating from a WSL-based install. The obfuscation and environment checks are designed to evade detection on typical developer machines and continuous integration systems. The malicious executable masquerades as a legitimate vite helper, although the package does not require any native helper, confirming the malicious nature of the payload.
Potential Impact
This malicious package enables persistent unauthorized code execution on Windows hosts via WSL by dropping and executing a binary at user login. This persistence mechanism can allow attackers to maintain foothold on affected systems, potentially leading to further compromise. The payload is specifically targeted to WSL environments with non-production NODE_ENV settings, reducing detection likelihood in standard environments.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing or using caldora version 1.0.0. If already installed in a WSL environment, users should check for and remove the 'vite-native-helper.exe' file from the Windows Startup folder to prevent persistent execution. Monitor for suspicious activity related to this executable. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Malicious code in caldora (npm)
Description
The npm package caldora version 1.0.0 contains malicious code that executes on import when run in a Linux environment with the Windows Subsystem for Linux (WSL) present and NODE_ENV not set to 'production'. It downloads a binary from a third-party file host and writes it as 'vite-native-helper.exe' into the Windows user's Startup folder, enabling persistent execution on the Windows host at next login. The payload is obfuscated by splitting the URL into parts and is dormant in typical developer or CI environments, targeting WSL developer hosts specifically. The package's declared functionality does not require this native helper, indicating malicious intent.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The caldora npm package version 1.0.0 runs a top-level asynchronous routine on import that, under specific conditions (Linux with /mnt/c present indicating WSL, and NODE_ENV not 'production'), constructs a URL from split strings to download a binary file named 'vite-native-helper.exe' from a third-party host (f004.backblazeb2.com). This binary is then written into the Windows Startup folder of the host user, ensuring it runs automatically on the next Windows login. This behavior establishes persistent code execution on the Windows host originating from a WSL-based install. The obfuscation and environment checks are designed to evade detection on typical developer machines and continuous integration systems. The malicious executable masquerades as a legitimate vite helper, although the package does not require any native helper, confirming the malicious nature of the payload.
Potential Impact
This malicious package enables persistent unauthorized code execution on Windows hosts via WSL by dropping and executing a binary at user login. This persistence mechanism can allow attackers to maintain foothold on affected systems, potentially leading to further compromise. The payload is specifically targeted to WSL environments with non-production NODE_ENV settings, reducing detection likelihood in standard environments.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing or using caldora version 1.0.0. If already installed in a WSL environment, users should check for and remove the 'vite-native-helper.exe' file from the Windows Startup folder to prevent persistent execution. Monitor for suspicious activity related to this executable. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12344
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735744bf8831d539159cb1
Added to database: 08/05/2026, 15:31:16 UTC
Last enriched: 08/05/2026, 17:21:22 UTC
Last updated: 08/05/2026, 17:21:22 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.