MAL-2026-12415
Malicious code in pfp-forms-sme-sitebuilder (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (97f0c2b9f45c8e537bcf70d98c1aa5daa263962eae954c2d871d978e0ac0dd64) index.js unconditionally requires./_support on module load. _support.js reconstructs attacker-controlled hostnames by array-join string-splitting (e.g. ["oob-worker.cf102-baf.w","orkers",".d","ev"].join("") and DNS-TXT fallback hosts like tin.dl.well1.site), downloads a platform-specific binary via https.get, writes it to a hidden staging path (/var/tmp/.cache_<hex> on Unix or %TEMP%/dotnet_diag_<hex>.exe on Windows) using a masquerade name, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe. Hostname string-splitting and dynamic reconstruction of API names (e.g. fs["chmod"+"Sync"]) constitute affirmative concealment. A sibling module lib/telemetry.js contains matching write+chmod+spawn dropper primitives with base64 chunk reassembly; it is not wired from index.js in this version but ships as a secondary dropper path. Fetch destinations are non-publisher, unpinned, and unverified; the fetched bytes are executed on the installer host on any require() of the package.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for pfp-forms-sme-sitebuilder (npm). Pin to a known-safe version or switch to an alternative.