VDB
KO

MAL-2026-12306

Malicious code in twork-products-taiga2-products-mobile (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (0870bb9f10cb88f264e25b839c6001a3b2c7d77777115871ba0e3c6f61ddb84b) On require of this package, index.js loads _init.js which selects a platform-specific endpoint, reconstructs destination hostnames at runtime from split-string arrays (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, with a DNS-TXT chunked-base64 fallback under *.dl.well1.site), downloads an opaque native binary over HTTPS, writes it to /tmp or %TEMP% under cover-story names such as.cache_<hex> or dotnet_diag_<hex>.exe, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe with stdio ignored. There is no hash or signature verification. Additional anti-analysis features are present: hostnames are assembled at runtime to evade static string scans, dropped files use benign-looking diagnostic/cache names, a marker file.analytics_state is written, and telemetry-opt-out environment variables (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) are honored as a cover story for the binary drop. The Cloudflare Workers hosts and DNS fallback domains have no relationship to any legitimate publisher of this package.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / twork-products-taiga2-products-mobile

No fixed version published yet for twork-products-taiga2-products-mobile (npm). Pin to a known-safe version or switch to an alternative.

References