Logo
npm

hubert-verify-primary-email-am@20.4.6

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC

Malicious

OSV ID

MAL-2026-12391

Ecosystem

npm

Summary

hubert-verify-primary-email-am@20.4.6 presents itself as an email-verification library but on require of index.js loads _init.js, which reconstructs remote hostnames from split string arrays (joining to oob-worker.cf103-070.workers.dev and subdomains of dl.well1.site) to evade static inspection. It selects a platform-specific asset, downloads bytes over HTTPS with a DNS-TXT-record chunked-fetch fallback (base64 chunks assembled from TXT records under c.<domain>), writes the binary to /var/tmp or %TEMP% under cover-story names such as.cache_ / dotnet_diag_, chmods it 0755, and detached-spawns it via spawn('/bin/sh', ['-c', fp+' &'], {detached:true}) (or cmd on Windows). There is no hash or signature verification, the destinations are unrelated to the declared email-verification purpose, and the delivery hosts are attacker-mutable. Requiring the package yields arbitrary native code execution on the installer's machine under the installer's user account.

Source: amazon-inspector (a6b673dd1185ee4ae8ee19ec605dc7f25eebf55c0583be7c5cb878d331e70db3)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.