MAL-2026-12285
Malicious code in tramvai-module-feature-toggle (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d8841208443b6595c8389bfac3e1cdb59a65ad0bc05a8dd3e01ca5c661287e56) On require() of the package, index.js loads setup.js which downloads a platform-specific binary from hardcoded Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev), writes it to a hidden temp path, chmods it 0755, and spawns it detached via /bin/sh. Destination hostnames are assembled at runtime via array split-join to evade string scanning, with benign-looking identifiers ('analytics_state', 'dotnet_diag_', '.cache_') and cover-story comments referencing 'telemetry' and 'CDN compatibility'. If the HTTPS fetch fails, setup.js reassembles a base64 payload from numbered DNS TXT records under attacker-controlled *.dl.well1.site domains (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site) as a covert delivery channel. Execution is gated by opt-out environment variables and a ~20912s lockfile cooldown. The package name resembles the legitimate tramvai ecosystem but ships no real functionality — the only effect of installation is the drop-and-execute pipeline.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for tramvai-module-feature-toggle (npm). Pin to a known-safe version or switch to an alternative.