Malicious code in native-hello-plugin (npm)
The native-hello-plugin version 1.2.0 for Windows-x64 contains a malicious prebuilt binary that executes a PowerShell command to fetch and run a remote script over unencrypted HTTP. This results in arbitrary code execution on the host when the plugin is loaded. The Linux-arm64 version is unaffected. No official patch or remediation guidance is currently provided.
AI Analysis
Technical Summary
The Windows-x64 prebuilt binary 'hello.node' in native-hello-plugin version 1.2.0 embeds a PowerShell command that downloads and executes a script from an unpinned, plaintext HTTP source (http://89.124.113.217:8000/update.ps1). This command is triggered at plugin startup via the N-API-exported 'sha256Hex' function called by the JavaScript wrapper's 'register()' method. This behavior enables arbitrary code execution on Windows hosts. The Linux-arm64 binary does not contain this malicious code, indicating targeted compromise of the Windows binary only.
Potential Impact
Loading the affected native-hello-plugin version 1.2.0 on Windows-x64 systems results in execution of arbitrary PowerShell code fetched from a remote attacker-controlled server. This can lead to full compromise of the host environment. The Linux-arm64 variant is not impacted.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid using native-hello-plugin version 1.2.0 on Windows-x64 until a fixed version is released. Consider removing the plugin and verifying system integrity if it was installed. Monitor vendor advisories for updates.
Malicious code in native-hello-plugin (npm)
Description
The native-hello-plugin version 1.2.0 for Windows-x64 contains a malicious prebuilt binary that executes a PowerShell command to fetch and run a remote script over unencrypted HTTP. This results in arbitrary code execution on the host when the plugin is loaded. The Linux-arm64 version is unaffected. No official patch or remediation guidance is currently provided.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Windows-x64 prebuilt binary 'hello.node' in native-hello-plugin version 1.2.0 embeds a PowerShell command that downloads and executes a script from an unpinned, plaintext HTTP source (http://89.124.113.217:8000/update.ps1). This command is triggered at plugin startup via the N-API-exported 'sha256Hex' function called by the JavaScript wrapper's 'register()' method. This behavior enables arbitrary code execution on Windows hosts. The Linux-arm64 binary does not contain this malicious code, indicating targeted compromise of the Windows binary only.
Potential Impact
Loading the affected native-hello-plugin version 1.2.0 on Windows-x64 systems results in execution of arbitrary PowerShell code fetched from a remote attacker-controlled server. This can lead to full compromise of the host environment. The Linux-arm64 variant is not impacted.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid using native-hello-plugin version 1.2.0 on Windows-x64 until a fixed version is released. Consider removing the plugin and verifying system integrity if it was installed. Monitor vendor advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13350
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a73851fbf8831d5394ef874
Added to database: 08/05/2026, 18:46:55 UTC
Last enriched: 08/05/2026, 23:16:54 UTC
Last updated: 08/05/2026, 23:16:54 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.