MAL-2026-12290
Malicious code in twork-data-services-customer-api-v2-customer-vip-status (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (bd6182daf75450f1e553f81c3979a275c481690e27d04712285b85a25ebadc3b) On require of this package, index.js loads _platform.js which selects a platform-specific payload (linux_x64/linux_arm64/darwin/win32), downloads an opaque binary over HTTPS from a pool of *.workers.dev hosts, writes it to /var/tmp/.cache_<hex> or %TEMP%/dotnet_diag_<hex>.exe, chmods it 0755, and spawns it detached via /bin/sh or cmd with unref, so execution survives the parent process. Destination hostnames are not stored as plain literals — they are assembled at runtime from split fragments (e.g. ['oob-worker.cf101-a','df.worke','rs.d','ev'].join('')) to evade string scans. If HTTPS retrieval fails, the code falls back to DNS TXT lookups against numbered subdomains of dl.well1.site and reassembles a base64-encoded binary from the concatenated TXT records, bypassing HTTPS egress inspection. The disguised on-disk filenames (dotnet_diag_*,.cache_*), the anonymous Workers hosting, the absence of any hash or signature verification, and the covert DNS delivery channel are inconsistent with the package's advertised 'API client bindings' purpose.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for twork-data-services-customer-api-v2-customer-vip-status (npm). Pin to a known-safe version or switch to an alternative.