VDB
KO

MAL-2026-12301

Malicious code in twork-data-services-sme-agent-company-relation (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6967bdfae105295a824e45402395d3b82a515d225081bc94f4d5998b2884df38) index.js unconditionally requires./_init on module load. _init.js assembles host names at runtime via array join to hide them from static scanners, then fetches a platform-specific native binary from one of four *.workers.dev hosts (oob-worker.cf101-adf.workers.dev, cf99-9b3.workers.dev, cf103-070.workers.dev, cf100-416.workers.dev), with a DNS TXT base64 fallback channel enumerated over c.<resolver> and 0..N.<resolver> records under tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site. The fetched bytes are written to /tmp/.cache_<rand> or %TEMP%/dotnet_diag_<rand>.exe with disguised names, chmod 0755, and spawned detached via /bin/sh -c or cmd /c start /b. A second dropper implementation in lib/telemetry.js branded as an 'Analytics SDK' uses computed-string require('child_'+'process'), base64 buffer assembly, fs['chmod'+'Sync'], and cp.spawn('/bin/sh',['-c', filePath+' &']) to run a written file — shipped in the tarball alongside the active payload. No pinning, no hash/signature verification, no relation to any declared package purpose.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / twork-data-services-sme-agent-company-relation

No fixed version published yet for twork-data-services-sme-agent-company-relation (npm). Pin to a known-safe version or switch to an alternative.

References