Logo
npm

finance-business-company-id-models@20.1.5

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC

Malicious

OSV ID

MAL-2026-12382

Ecosystem

npm

Summary

On require() of this package, index.js loads _compat.js which reconstructs destination hostnames from string-split arrays (e.g. "oob-worker.cf102-baf.workers"+".d"+".ev") to fetch a platform-specific binary via https.get, with a DNS-TXT chunked fallback across tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site. The downloaded bytes are written to /var/tmp or %TEMP% under disguised names (.cache_<rand>, dotnet_diag_<rand>.exe, .analytics_state), chmod'd 0755, and spawned detached via cp.spawn("/bin/sh", ["-c", fp+" &"], {detached:true}) on POSIX or cmd.exe /c start /b on Windows, with no hash or signature verification. lib/telemetry.js contains a second dropper of the same shape, loading child_process via require("child_"+"process") string-split, assembling a base64-chunk buffer, and chmod+exec'ing an "extension" path. The package's stated purpose is a "company id models" library; the network destinations, obfuscation, cover-story filenames, and platform-gated execution are unrelated to that purpose and match a supply-chain dropper campaign.

Source: amazon-inspector (d324092012d8b7c4dda17720255575963c9e35fcd86e254541cdf7abb5edffcf)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.