VDB
EN

MAL-2026-12287

Malicious code in twork-data-services-aggregator-company-sme-main-timeline-loader-with-customers (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (401d167bfbb3ec350a033f908aef6678495563e92c6b090d0eaab85bd1c2b7ba) On require(), index.js loads _bridge.js which assembles obfuscated Cloudflare Workers hostnames from split string literals (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev) and downloads a platform-specific opaque binary via https.get. If HTTPS fails, a DNS-TXT covert-channel fallback queries c.<domain> for a chunk count then <i>.<domain> TXT records under tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site, base64-decoding the concatenated chunks. The bytes are written to a hidden path in /tmp or %TEMP%, chmodded 0755, and executed detached via spawn("/bin/sh", ["-c", fp+" &"]) or spawn("cmd",...). Cover strings such as "analytics_state" and "dotnet_diag" mask the behavior. The hosts are unrelated to any declared publisher, the fetched content is opaque and unverified, and execution fires automatically when any consumer imports the package.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / twork-data-services-aggregator-company-sme-main-timeline-loader-with-customers

No fixed version published yet for twork-data-services-aggregator-company-sme-main-timeline-loader-with-customers (npm). Pin to a known-safe version or switch to an alternative.

참고