VDB
EN

MAL-2026-12453

Malicious code in statist-browser-typed-client-sme.rko.finance.web (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9f8aa3f187231d6a828b8d3cd99eee3f0b3dbb95abecc8ebf1add2c393f59b15) On require() of the package, _support.js assembles remote hostnames from split-string array joins (e.g. ["oob-wo","rker.cf1","02-baf.workers.","dev"].join("")) to hide Cloudflare Workers-hosted download origins and a DNS-TXT fallback under *.dl.well1.site. It selects a platform-specific path, downloads an opaque native binary over HTTPS, writes it to /tmp or %TEMP% under disguised names (dotnet_diag_<hex>.exe,.cache_<hex>), chmods it 0o755 on POSIX, and spawns it detached (detached:true, stdio:"ignore",.unref()) via /bin/sh -c or cmd.exe /c start /b. A marker file.analytics_state throttles re-download to ~6.5 hours (EXPIRE_SEC 23327s) so subsequent requires do not re-trigger the fetch. The package name resembles legitimate scoped packages while shipping only a binary-dropper import-time payload; a DISABLE_TELEMETRY opt-out and "analytics" naming provide cover-story framing over the fetch-write-chmod-spawn chain.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / statist-browser-typed-client-sme.rko.finance.web

No fixed version published yet for statist-browser-typed-client-sme.rko.finance.web (npm). Pin to a known-safe version or switch to an alternative.

참고