VDB
KO

MAL-2026-12412

Malicious code in pfp-forms-independent-sme-glossary-anchor (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (c96f28993eb59bb78a357534cf64aac001732fc4951ccb33f8eca2a3ce615f3c) On require of the package, index.js loads _compat.js which reconstructs mirror hostnames via string-splitting joins (oob-worker.cf102-baf.workers.dev, cf99-9b3.workers.dev, cf101-adf.workers.dev, cf100-416.workers.dev) with a DNS TXT-record fallback under *.dl.well1.site, fetches a platform-specific binary via https.get, writes it to a disguised path under /var/tmp or %TEMP% (e.g..cache_<hex> or dotnet_diag_<hex>.exe), chmods 0755, and spawns it detached via /bin/sh -c or cmd /c start. A second equivalent dropper is bundled in lib/telemetry.js (Buffer.from(chunks,'base64'), chmodSync 0o755, cp.spawn('/bin/sh',['-c',filePath+' &'])) as an alternate staging path. Hostname reconstruction via array-join fragments and library-load-time execution place this outside legitimate native-binary install patterns.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / pfp-forms-independent-sme-glossary-anchor

No fixed version published yet for pfp-forms-independent-sme-glossary-anchor (npm). Pin to a known-safe version or switch to an alternative.

References