MAL-2026-12296
Malicious code in twork-data-services-product-design-data (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (1a86edfca41ff32a7b044ecb921977944dbdc5cf5d2a3ccae4e5ca001a851816) On require of the package's main module, _loader.js downloads a platform-specific binary from a set of obfuscated Cloudflare Workers subdomains (oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev) — reconstructed at runtime from split string arrays — with a DNS TXT chunked-base64 fallback over *.dl.well1.site (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site). The fetched bytes are written to /var/tmp or %TEMP% under cover names such as.cache_<hex> and dotnet_diag_<hex>.exe, chmodded 0755, and spawned detached via /bin/sh -c or cmd.exe /c start /b. A parallel dropper implementation is bundled at lib/telemetry.js dressed as an APM/telemetry SDK, using base64 chunk assembly (Buffer.from(chunks,'base64')), string-concatenated fs['chmod'+'Sync'] to set 0755, and cp.spawn('/bin/sh', ['-c', filePath+' &']). The string-split concealment of C2 hostnames, DNS exfil domains, and the child_process module name is deliberate static-analysis evasion.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for twork-data-services-product-design-data (npm). Pin to a known-safe version or switch to an alternative.