Logo
npm

invest-module-cookie@20.8.2

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 1:33 PM UTC

Malicious

OSV ID

MAL-2026-12393

Ecosystem

npm

Summary

On require('invest-module-cookie'), index.js loads _adapter.js which selects an OS-specific asset path, downloads an opaque binary from one of three obfuscated *.workers.dev hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS-TXT covert-channel fallback that base64-reassembles chunks from *.dl.well1.site (tin/tina/ldr/win subdomains), writes the payload to /var/tmp or %TEMP% under a disguised name, chmods it 0755, and detaches-spawns it via /bin/sh -c or cmd.exe. Destination hostnames are assembled at runtime from split string fragments (e.g. ['oob-worker.cf102-baf.wo','rkers.dev'].join('')) to defeat static host-scanning. The package is advertised as reusable cookie module components, and the fetched binary bears no relationship to that stated purpose; publisher identity does not match any of the hardcoded hosts.

Source: amazon-inspector (6c3f53c4d50d2dedd530c65015b26a902950e6e2bbef3cda3560a661d4aad178)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.