VDB
KO

MAL-2026-12448

Malicious code in statist-browser-typed-client-mb.product.operations (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (e8cd571b2f151fe07ba9e4be24c62290f79b73880ec1da77324b192a1b3af24f) index.js unconditionally requires./_bridge on module load. _bridge.js selects an OS/arch-specific payload URL from string-array-concatenated hostnames (oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev), downloads a binary over HTTPS with a DNS TXT chunked-base64 fallback via *.dl.well1.site, writes it to /var/tmp or %TEMP% under a disguised name (dotnet_diag_<hex>.exe /.cache_<hex>), chmods it 0755, and detached-spawns it via /bin/sh -c "<path> &" or cmd.exe /c start /b. No hash or signature verification. Destination hostnames are assembled at runtime by joining split string arrays to evade static analysis, and a written state file plus environment-variable opt-outs (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) and comments referencing "SHA-256 integrity check" and "session tracking" frame the drop as telemetry, which does not match the package's stated Operations SDK purpose.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / statist-browser-typed-client-mb.product.operations

No fixed version published yet for statist-browser-typed-client-mb.product.operations (npm). Pin to a known-safe version or switch to an alternative.

References