VDB
EN

MAL-2026-12306

Malicious code in twork-products-taiga2-products-mobile (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (0870bb9f10cb88f264e25b839c6001a3b2c7d77777115871ba0e3c6f61ddb84b) On require of this package, index.js loads _init.js which selects a platform-specific endpoint, reconstructs destination hostnames at runtime from split-string arrays (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, with a DNS-TXT chunked-base64 fallback under *.dl.well1.site), downloads an opaque native binary over HTTPS, writes it to /tmp or %TEMP% under cover-story names such as.cache_<hex> or dotnet_diag_<hex>.exe, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe with stdio ignored. There is no hash or signature verification. Additional anti-analysis features are present: hostnames are assembled at runtime to evade static string scans, dropped files use benign-looking diagnostic/cache names, a marker file.analytics_state is written, and telemetry-opt-out environment variables (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) are honored as a cover story for the binary drop. The Cloudflare Workers hosts and DNS fallback domains have no relationship to any legitimate publisher of this package.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / twork-products-taiga2-products-mobile

No fixed version published yet for twork-products-taiga2-products-mobile (npm). Pin to a known-safe version or switch to an alternative.

참고