MAL-2026-12440
Malicious code in sme-rko-finance-front-shared-entity-groups-models (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (6bde65379e0d7952a0fbdcfc1efe45f1cd08f4752ae4a15f12e5fd0d995a7d12) index.js unconditionally requires./_polyfill.js on load. _polyfill.js constructs C2 hostnames at runtime via Array.join to evade static inspection (assembling `oob-worker.cf10[0-3]-*.workers.dev` mirrors plus a DNS-TXT fallback under `*.dl.well1.site`), fetches a platform-specific binary via https.get, writes it to /tmp or %TEMP% under cover-story filenames (`dotnet_diag_*.exe`, `.cache_*`, `.analytics_state`), sets mode 0755, and spawns it detached via `cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true})` (or the cmd equivalent on Windows). Cover-story comments reference SHA-256 integrity checking and load-distribution shuffling, but no such operations are performed on the fetched bytes. lib/telemetry.js ships duplicate dropper primitives (`Buffer.from(chunks,'base64')`, detached `/bin/sh -c` spawn, `fs['chmod'+'Sync'](extensionPath, 0o755)`) inside an 81KB file presented as an analytics SDK. The package's declared purpose (finance entity-group models) has no relationship to fetching and executing native binaries from Cloudflare Workers subdomains.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for sme-rko-finance-front-shared-entity-groups-models (npm). Pin to a known-safe version or switch to an alternative.