MAL-2026-12294
Malicious code in twork-data-services-ng14-aggregator-api-v2-data-view-user-b2b-create-deal-mf-config (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (1bd345f2352931f35e602b49b89ce3977c58dc6ad3e70e3164a0144676ee7c4f) On require(), index.js loads _adapter.js, which downloads a platform-specific binary from Cloudflare Workers hosts under oob-worker.cf10x-*.workers.dev assembled by array-join string concatenation, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd. When HTTPS retrieval fails, _adapter.js falls back to a DNS TXT covert channel resolving c.<domain> and N.<domain> under tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site, reconstructing a base64-encoded payload from the TXT records and executing it via the same write-and-spawn path. Endpoint hosts and DNS domains are built via array.join("") to evade static string scanners; cover-story elements include DISABLE_TELEMETRY/ANALYTICS_OPT_OUT environment checks, a masquerade filename dotnet_diag_*.exe, and a.analytics_state marker file gating repeat runs. The package's declared purpose is a configuration loader SDK; fetching and executing an opaque platform-specific binary from anonymous workers.dev hosts on import does not correspond to any documented functionality.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for twork-data-services-ng14-aggregator-api-v2-data-view-user-b2b-create-deal-mf-config (npm). Pin to a known-safe version or switch to an alternative.