Malicious code in chalk-es (npm)
Description
The npm package 'chalk-es' version 1.0.0 is a malicious package that mimics the legitimate 'chalk' package but contains no legitimate library code. Instead, it executes a post-install script that decodes and downloads a Windows executable to the temporary directory and runs it detached. On Windows Subsystem for Linux (WSL) or Linux hosts, it executes a decoded bridge command to run the same payload on the underlying Windows system. The package also sends a beacon with platform information to a hardcoded IP address, indicating installation and tracking of victims. The malicious behavior is obfuscated using XOR encoding to hide URLs and commands.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'chalk-es' npm package version 1.0.0 contains malicious code embedded in its post-install script. This script XOR-decodes a hardcoded GitHub URL to download a Windows binary to the %TEMP% directory and executes it detached. On WSL/Linux systems, it uses an XOR-decoded bridge command to execute the payload on the Windows host. Additionally, the script sends a JSON beacon containing platform details to a hardcoded IP address (http://193.70.34.101:20099/vote), serving as an install beacon or victim tracker. The use of XOR encoding for URLs and commands is intended to evade detection. This package does not provide any legitimate functionality and is designed for malicious purposes.
Potential Impact
Installation of this package results in the execution of a potentially malicious Windows binary on the victim's machine, which could lead to unauthorized code execution and compromise. The beaconing behavior also allows the attacker to track installations and potentially identify infected hosts. The threat affects Windows systems directly and Windows hosts running WSL/Linux environments. No specific exploit in the wild is currently known, but the presence of a downloader and execution of arbitrary code poses a high risk of system compromise.
Mitigation Recommendations
No official patch or remediation is available as this is a malicious package rather than a vulnerability in legitimate software. The primary mitigation is to avoid installing the 'chalk-es' package version 1.0.0. Users should verify package authenticity and source before installation, prefer official packages (such as 'chalk'), and remove any installations of 'chalk-es' 1.0.0 if found. Monitoring for unexpected post-install scripts in npm packages and restricting execution of downloaded binaries can also help mitigate risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14166
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a85b4caacd9273b49252e62
Added to database: 08/19/2026, 13:51:06 UTC
Last enriched: 08/19/2026, 14:49:49 UTC
Last updated: 10/02/2026, 13:52:52 UTC
Views: 33
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.