MAL-2026-12486
Malicious code in travel-core-typings-reducers (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (3f8a32e0a10123bde764e059abea762d4b0574d57d35e6bd3e92e4d96cdeb245) On require() of the package, index.js loads _ext.js which downloads a platform-specific binary from runtime-assembled Cloudflare workers.dev hostnames (oob-worker.cf99-9b3.workers.dev, cf100-416, cf101-adf, cf103-070) with a DNS-TXT covert-channel fallback against subdomains of dl.well1.site (tin/ldr/win.dl.well1.site) that reassembles base64 chunks into executable bytes. The fetched payload is written to /var/tmp or %TEMP% under disguised names (.cache_<rand> on Unix, dotnet_diag_<rand>.exe on Windows), chmod +x'd, and spawned detached via spawn("/bin/sh",["-c",fp+" &"],{detached:true}) or spawn("cmd",...). C2 hostnames are assembled at runtime via ["oob-work","er.cf103-07","0.workers.","dev"].join("") to defeat static string search. The package presents itself as a base framework typings module and ships an unreferenced lib/telemetry.js plus DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK opt-out env vars as cover; the DNS-TXT path carries an inline comment describing it as chunked transfer for environments blocking HTTPS.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for travel-core-typings-reducers (npm). Pin to a known-safe version or switch to an alternative.