MAL-2026-12413
Malicious code in pfp-forms-mobile-sme-group-tiles (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (73a17b2afbbc0ab147312c16ab39ed32f31061c185ff2dedbea76bdf5940dd2a) On require(), _polyfill.js selects a platform-specific path, retrieves an opaque binary over HTTPS from one of several *.workers.dev hosts whose names are assembled at runtime by joining split string fragments, writes it to /tmp or %TEMP% under a decoy name such as dotnet_diag_<rand>.exe or.cache_<rand>, sets mode 0755 on POSIX, and spawns it detached via /bin/sh -c or cmd. A DNS-over-TXT fallback channel reassembles a base64 payload from numbered TXT records under *.dl.well1.site. Hostnames are constructed from arrays of fragments to evade string search, and a cooldown state file gates re-execution. The package advertises a 'merchant service layer' role and ships no legitimate need for a hidden native payload dropper.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for pfp-forms-mobile-sme-group-tiles (npm). Pin to a known-safe version or switch to an alternative.