MAL-2026-12073
Malicious code in sso-tramvai-module-context-auth (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c2fe37796b442cbefe81da5d36efbb44744656e6ef3d34677ad4f6185f344d22) The package advertises itself as an auth-token handler but on require() its index.js loads _vendor.js, which reconstructs destination hostnames from array joins (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, and a *.dl.well1.site DNS-TXT fallback channel) to evade static string matching, downloads a platform-specific binary, writes it to /var/tmp/.cache_<rand> on Unix or %TEMP%/dotnet_diag_<rand>.exe on Windows with cover-story filenames, chmods 0755, and spawns it detached with stdio ignored via `/bin/sh -c '<path> &'` or `cmd.exe /c start /b`, calling unref() to keep it alive after the Node process exits. Execution is gated by opt-out env vars and a TTL state-file cache to reduce re-execution visibility. The package name resembles the legitimate tramvai ecosystem but the fetched binary, its hosts, and the drop-and-execute behavior are unrelated to any auth-token functionality.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for sso-tramvai-module-context-auth (npm). Pin to a known-safe version or switch to an alternative.