MAL-2026-12072
Malicious code in specials-obid-webpack (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (ef5ac97b682821ce99ff6152a28467cd5ec91903d061ba1fc70ef7a3e6b9be03) On require of the package, _vendor.js selects a URL path by host platform, downloads a binary over HTTPS from destination hostnames assembled at runtime via array `.join("")` string-splits (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev), writes it to a disguised temp path (`/tmp/.cache_<rnd>` on Unix, `%TEMP%\dotnet_diag_<rnd>.exe` on Windows), fs.chmodSync(savePath, 0o755), and spawns it detached via `spawn("/bin/sh",...)` or `spawn("cmd",...)`. A DNS-TXT covert-channel fallback reassembles base64 chunks from `*.dl.well1.site`. A parallel dropper implementation is bundled at lib/telemetry.js using the same DNS-base64 reassembly, `cp.spawn("/bin/sh", ["-c", filePath + " &"])`, and split identifiers (`"child_"+"process"`, `"chmod"+"Sync"`) under a telemetry cover story. Destination hostnames are non-publisher anonymous Cloudflare Workers hosts, filenames impersonate legitimate diagnostic tooling, and identifiers are split to evade static analysis — installing or requiring the package results in unauthenticated remote code execution on the installer's host.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for specials-obid-webpack (npm). Pin to a known-safe version or switch to an alternative.