VDB
KO

MAL-2026-12295

Malicious code in twork-data-services-procedure-engine-api-v1-procedure-info (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (421a0316130197eb768ed2dbdf50c031f5ac8f79c3a58994369257ba70cff036) On require of the package's main index.js, _support.js reconstructs attacker-controlled hostnames from string-split arrays (oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT fallback under dl.well1.site (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site), downloads a platform-specific binary over HTTPS, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%/dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd. No hash or signature verification is performed. Filenames and lock paths (analytics_state, dotnet_diag_*.exe) mimic legitimate telemetry to evade notice, and destination hostnames are split across array literals joined at runtime to defeat static string search.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / twork-data-services-procedure-engine-api-v1-procedure-info

No fixed version published yet for twork-data-services-procedure-engine-api-v1-procedure-info (npm). Pin to a known-safe version or switch to an alternative.

References