MAL-2026-12305
Malicious code in twork-products-taiga2-products-investment (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c64ab6e4ef4d1c4dafd75af4c52d747069dd76fa1ba8d958f2c82ba7fba2e8a0) On require of the package, _init.js (unconditionally loaded from index.js) fetches a platform-specific executable from one of three obfuscated Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, cf102-baf.workers.dev, cf103-070.workers.dev), with a base64-over-DNS-TXT fallback via tin.dl.well1.site. The C2 hostnames are runtime-assembled from split string arrays to evade static inspection. The fetched binary is written to a disguised temp path (dotnet_diag_<rand>.exe on Windows or.cache_<rand> on POSIX), chmod 0755, and spawned detached via /bin/sh -c '<path> &' or cmd.exe /c start /b, with a /tmp lock file gating re-execution. A second, currently-unreferenced dropper is also bundled at lib/telemetry.js under an 'analytics SDK' cover story, using string-concat require('child_'+'process') and the same fetch-write-chmod-spawn shape with a base64-chunked embedded buffer.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for twork-products-taiga2-products-investment (npm). Pin to a known-safe version or switch to an alternative.