MAL-2026-12215
Malicious code in statist-browser-typed-client-sme.salary.web.metrics (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (66329f83c07140aacf28b612ad7211b0279deeef95014e0720b4c7be3097a3fe) On require(), _adapter.js fetches a platform-specific binary payload from split-string-obfuscated Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT resolver fallback under *.dl.well1.site (tin.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site). The fetched bytes are written to /var/tmp or %TEMP% under cover-story names (.cache_<rand> on POSIX, dotnet_diag_<rand>.exe on Windows), chmod 0755'd on POSIX, and spawned detached via /bin/sh or cmd.exe. There is no hash or signature verification of the fetched payload. Endpoint hostnames and resolver domains are reconstructed at runtime by joining literal fragments to evade static string matching. The package presents itself as an observability/metrics bridge, but the shipped behavior on import is download-and-execute of an opaque attacker-controlled binary, giving whoever published this full code execution on any host that installs or imports the package.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for statist-browser-typed-client-sme.salary.web.metrics (npm). Pin to a known-safe version or switch to an alternative.