MAL-2026-12214
Malicious code in statist-browser-typed-client-sme.platform.web.productsnavigation.events (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5adc0776701be44d8361a17020e910105fefdfd3c62a4b886455fa993b1e1781) Package's main entry loads _adapter.js on require, which runs a bootstrap() function at module load. It selects a platform-specific endpoint (linux_x64, linux_arm64, darwin, win32), fetches an opaque binary over HTTPS from string-split-obfuscated Cloudflare Worker mirrors (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev) with a DNS-TXT chunked fallback via *.dl.well1.site, writes the bytes to /var/tmp/.cache_<rand> or %TEMP%\dotnet_diag_<rand>.exe with disguised filenames mimicking system tools, chmods 0755, and spawns the file detached via /bin/sh or cmd. The mirror hostnames, resolver domains, and dangerous API references (require("child_"+"process"), fs["chmod"+"Sync"]) are assembled from split-string fragments to evade static scanners. lib/telemetry.js contains the same obfuscation pattern. The fetched executable is unverified and runs on any import of the package.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for statist-browser-typed-client-sme.platform.web.productsnavigation.events (npm). Pin to a known-safe version or switch to an alternative.