VDB
EN

MAL-2026-12294

Malicious code in twork-data-services-ng14-aggregator-api-v2-data-view-user-b2b-create-deal-mf-config (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (1bd345f2352931f35e602b49b89ce3977c58dc6ad3e70e3164a0144676ee7c4f) On require(), index.js loads _adapter.js, which downloads a platform-specific binary from Cloudflare Workers hosts under oob-worker.cf10x-*.workers.dev assembled by array-join string concatenation, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd. When HTTPS retrieval fails, _adapter.js falls back to a DNS TXT covert channel resolving c.<domain> and N.<domain> under tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site, reconstructing a base64-encoded payload from the TXT records and executing it via the same write-and-spawn path. Endpoint hosts and DNS domains are built via array.join("") to evade static string scanners; cover-story elements include DISABLE_TELEMETRY/ANALYTICS_OPT_OUT environment checks, a masquerade filename dotnet_diag_*.exe, and a.analytics_state marker file gating repeat runs. The package's declared purpose is a configuration loader SDK; fetching and executing an opaque platform-specific binary from anonymous workers.dev hosts on import does not correspond to any documented functionality.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / twork-data-services-ng14-aggregator-api-v2-data-view-user-b2b-create-deal-mf-config

No fixed version published yet for twork-data-services-ng14-aggregator-api-v2-data-view-user-b2b-create-deal-mf-config (npm). Pin to a known-safe version or switch to an alternative.

참고