-= Per source details. Do not edit below this line.=-
On import of index.mjs, setImmediate invokes a _syncWorkspace routine whose network destination and paths are reconstructed at runtime from hex-encoded string arrays (a _cfg object decoded via Buffer.from(s,'hex').toString()). The decoded host is f004.backblazeb2.com and the path prefix is /file/dp8hbvocjd2fpza/. Execution is gated on Linux with WSL_DISTRO_NAME set. The code downloads helper.tar.gz and a background-service binary via https.get, writes them to disk, extracts the tarball with tar -xzf, chmods the service to 0755, and launches it detached with.unref(). It then reaches through the WSL /mnt/c mount into the Windows host filesystem, drops vite.exe under %APPDATA%\Local\Microsoft\Windows\syscache, and writes env-setup.cmd into %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ containing start /b /min "" "[BIN]" so the fetched Windows binary runs minimized on every login. The stated purpose of the package is calendar/streak math; none of the fetched hosts, opaque binaries, hex-obfuscated identifiers, or Windows Startup writes align with that purpose. Combined signals present: import-time auto-execution, hex-obfuscated attacker-controlled host, unpinned/unverified binary download and execute, WSL-to-Windows-host escape, and login persistence.
1.0.0Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H