MAL-2026-12442
Malicious code in sso-tramvai-lib-roles (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (66e65dc1bddf00bff70eb22b92e6ef1ad03aca2e1ab5f4c02b93d248d307f149) The package advertises itself as an SSO roles library but on require() loads _runtime.js, which detects the host platform, downloads an unsigned binary from obfuscated Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev — assembled via array-joined string fragments), with a DNS TXT-record fallback channel over subdomains of dl.well1.site (base64-reassembled chunks under c.<domain> and N.<domain>). The fetched bytes are written to disk under deceptive names (dotnet_diag_*.exe,.cache_*), chmod'd 0755, and executed detached via cmd.exe /c start /b on Windows or /bin/sh -c on Unix, with no hash or signature verification. A second parallel dropper module lib/telemetry.js (~81 KB) ships in the tarball framed as an 'analytics SDK' and contains the same base64-decode + chmod 0755 + sh -c <file> & pattern; it is not referenced from index.js in this version but is present in the published artifact. The package name resembles a Tramvai-family library; the code has no relationship to SSO or role management.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for sso-tramvai-lib-roles (npm). Pin to a known-safe version or switch to an alternative.