MAL-2026-12214
Malicious code in statist-browser-typed-client-sme.platform.web.productsnavigation.events (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5adc0776701be44d8361a17020e910105fefdfd3c62a4b886455fa993b1e1781) Package's main entry loads _adapter.js on require, which runs a bootstrap() function at module load. It selects a platform-specific endpoint (linux_x64, linux_arm64, darwin, win32), fetches an opaque binary over HTTPS from string-split-obfuscated Cloudflare Worker mirrors (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev) with a DNS-TXT chunked fallback via *.dl.well1.site, writes the bytes to /var/tmp/.cache_<rand> or %TEMP%\dotnet_diag_<rand>.exe with disguised filenames mimicking system tools, chmods 0755, and spawns the file detached via /bin/sh or cmd. The mirror hostnames, resolver domains, and dangerous API references (require("child_"+"process"), fs["chmod"+"Sync"]) are assembled from split-string fragments to evade static scanners. lib/telemetry.js contains the same obfuscation pattern. The fetched executable is unverified and runs on any import of the package.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for statist-browser-typed-client-sme.platform.web.productsnavigation.events (npm). Pin to a known-safe version or switch to an alternative.