Malicious code in quorvex (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (9127b24fd8619b810163b5b5714d580951a3a96cfa1b37e63a57ff3cc9c2cca5) [email protected] ships index.mjs as the package main, containing a base64-encoded Windows PE (~355KB) in a PAYLOAD constant. At import time on Windows hosts with more than 4GB of RAM, the code decodes the payload and writes it to %APPDATA%/Microsoft/Windows/Start Menu/Programs/Startup/vite-native-helper.exe, causing Windows to auto-execute the dropped binary at the next user logon. The README self-describes the package as a placeholder with 'nothing in here yet' while documenting deliberate anti-tree-shaking design ('index.mjs performs a real import-time assignment... that no bundler can prove is inert') to ensure the drop runs when the module is loaded. The vite-native-helper.exe filename and Vite-adjacent naming are a cover story; the memory-size gate is a sandbox-evasion check. Installing or importing this package on a Windows host results in an opaque attacker-controlled binary being placed in the user's Startup folder with logon-time persistence.
AI Analysis
Technical Summary
The quorvex npm package versions 0.2.0 and 0.2.1 include a main module (index.mjs) that contains a base64-encoded Windows PE binary embedded as a constant. When imported on Windows systems with over 4GB of RAM, the code decodes and writes this binary to the Startup folder (%APPDATA%/Microsoft/Windows/Start Menu/Programs/Startup/vite-native-helper.exe), causing it to execute automatically at the next user logon. The package employs a memory size check as a sandbox evasion technique and uses naming related to 'vite' to disguise the malicious payload. The README misleads users by claiming the package is a placeholder with no functionality, while the code is designed to run at import time and evade static analysis.
Potential Impact
Installing or importing the quorvex package on a Windows host with more than 4GB of RAM results in the silent installation of an attacker-controlled executable that gains persistence by auto-executing at user logon. This can lead to unauthorized code execution and potential compromise of the affected system. The persistence mechanism leverages the Windows Startup folder, making the threat persistent across reboots.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. Users and administrators should avoid installing or importing the quorvex package versions 0.2.0 and 0.2.1. Remove any instances of the 'vite-native-helper.exe' file from the Startup folder if present. Employ npm package reputation checks and use trusted sources to prevent installation of malicious packages. Monitor for and block suspicious executables in user Startup folders on Windows systems.
Malicious code in quorvex (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (9127b24fd8619b810163b5b5714d580951a3a96cfa1b37e63a57ff3cc9c2cca5) [email protected] ships index.mjs as the package main, containing a base64-encoded Windows PE (~355KB) in a PAYLOAD constant. At import time on Windows hosts with more than 4GB of RAM, the code decodes the payload and writes it to %APPDATA%/Microsoft/Windows/Start Menu/Programs/Startup/vite-native-helper.exe, causing Windows to auto-execute the dropped binary at the next user logon. The README self-describes the package as a placeholder with 'nothing in here yet' while documenting deliberate anti-tree-shaking design ('index.mjs performs a real import-time assignment... that no bundler can prove is inert') to ensure the drop runs when the module is loaded. The vite-native-helper.exe filename and Vite-adjacent naming are a cover story; the memory-size gate is a sandbox-evasion check. Installing or importing this package on a Windows host results in an opaque attacker-controlled binary being placed in the user's Startup folder with logon-time persistence.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The quorvex npm package versions 0.2.0 and 0.2.1 include a main module (index.mjs) that contains a base64-encoded Windows PE binary embedded as a constant. When imported on Windows systems with over 4GB of RAM, the code decodes and writes this binary to the Startup folder (%APPDATA%/Microsoft/Windows/Start Menu/Programs/Startup/vite-native-helper.exe), causing it to execute automatically at the next user logon. The package employs a memory size check as a sandbox evasion technique and uses naming related to 'vite' to disguise the malicious payload. The README misleads users by claiming the package is a placeholder with no functionality, while the code is designed to run at import time and evade static analysis.
Potential Impact
Installing or importing the quorvex package on a Windows host with more than 4GB of RAM results in the silent installation of an attacker-controlled executable that gains persistence by auto-executing at user logon. This can lead to unauthorized code execution and potential compromise of the affected system. The persistence mechanism leverages the Windows Startup folder, making the threat persistent across reboots.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. Users and administrators should avoid installing or importing the quorvex package versions 0.2.0 and 0.2.1. Remove any instances of the 'vite-native-helper.exe' file from the Startup folder if present. Employ npm package reputation checks and use trusted sources to prevent installation of malicious packages. Monitor for and block suspicious executables in user Startup folders on Windows systems.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12422
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735730bf8831d53913cd70
Added to database: 08/05/2026, 15:30:56 UTC
Last enriched: 08/05/2026, 15:39:04 UTC
Last updated: 08/05/2026, 15:39:17 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.