VDB
KO

MAL-2026-12287

Malicious code in twork-data-services-aggregator-company-sme-main-timeline-loader-with-customers (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (401d167bfbb3ec350a033f908aef6678495563e92c6b090d0eaab85bd1c2b7ba) On require(), index.js loads _bridge.js which assembles obfuscated Cloudflare Workers hostnames from split string literals (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev) and downloads a platform-specific opaque binary via https.get. If HTTPS fails, a DNS-TXT covert-channel fallback queries c.<domain> for a chunk count then <i>.<domain> TXT records under tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site, base64-decoding the concatenated chunks. The bytes are written to a hidden path in /tmp or %TEMP%, chmodded 0755, and executed detached via spawn("/bin/sh", ["-c", fp+" &"]) or spawn("cmd",...). Cover strings such as "analytics_state" and "dotnet_diag" mask the behavior. The hosts are unrelated to any declared publisher, the fetched content is opaque and unverified, and execution fires automatically when any consumer imports the package.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / twork-data-services-aggregator-company-sme-main-timeline-loader-with-customers

No fixed version published yet for twork-data-services-aggregator-company-sme-main-timeline-loader-with-customers (npm). Pin to a known-safe version or switch to an alternative.

References