Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in quorvex (npm)

0
High
Published: 08/05/2026 (08/05/2026, 12:25:31 UTC)
Source: GCVE Database
Product: quorvex

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (9127b24fd8619b810163b5b5714d580951a3a96cfa1b37e63a57ff3cc9c2cca5) [email protected] ships index.mjs as the package main, containing a base64-encoded Windows PE (~355KB) in a PAYLOAD constant. At import time on Windows hosts with more than 4GB of RAM, the code decodes the payload and writes it to %APPDATA%/Microsoft/Windows/Start Menu/Programs/Startup/vite-native-helper.exe, causing Windows to auto-execute the dropped binary at the next user logon. The README self-describes the package as a placeholder with 'nothing in here yet' while documenting deliberate anti-tree-shaking design ('index.mjs performs a real import-time assignment... that no bundler can prove is inert') to ensure the drop runs when the module is loaded. The vite-native-helper.exe filename and Vite-adjacent naming are a cover story; the memory-size gate is a sandbox-evasion check. Installing or importing this package on a Windows host results in an opaque attacker-controlled binary being placed in the user's Startup folder with logon-time persistence.

Affected software

npmghsa
quorvex
Affected versions
=0.2.1=0.2.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 15:39:04 UTC

Technical Analysis

The quorvex npm package versions 0.2.0 and 0.2.1 include a main module (index.mjs) that contains a base64-encoded Windows PE binary embedded as a constant. When imported on Windows systems with over 4GB of RAM, the code decodes and writes this binary to the Startup folder (%APPDATA%/Microsoft/Windows/Start Menu/Programs/Startup/vite-native-helper.exe), causing it to execute automatically at the next user logon. The package employs a memory size check as a sandbox evasion technique and uses naming related to 'vite' to disguise the malicious payload. The README misleads users by claiming the package is a placeholder with no functionality, while the code is designed to run at import time and evade static analysis.

Potential Impact

Installing or importing the quorvex package on a Windows host with more than 4GB of RAM results in the silent installation of an attacker-controlled executable that gains persistence by auto-executing at user logon. This can lead to unauthorized code execution and potential compromise of the affected system. The persistence mechanism leverages the Windows Startup folder, making the threat persistent across reboots.

Mitigation Recommendations

No official patch or remediation is currently documented for this malicious package. Users and administrators should avoid installing or importing the quorvex package versions 0.2.0 and 0.2.1. Remove any instances of the 'vite-native-helper.exe' file from the Startup folder if present. Employ npm package reputation checks and use trusted sources to prevent installation of malicious packages. Monitor for and block suspicious executables in user Startup folders on Windows systems.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-12422
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a735730bf8831d53913cd70

Added to database: 08/05/2026, 15:30:56 UTC

Last enriched: 08/05/2026, 15:39:04 UTC

Last updated: 08/05/2026, 15:39:17 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses