invest-module-cookie@20.8.2
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 1:33 PM UTC
OSV ID
MAL-2026-12393
Ecosystem
npm
Summary
On require('invest-module-cookie'), index.js loads _adapter.js which selects an OS-specific asset path, downloads an opaque binary from one of three obfuscated *.workers.dev hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS-TXT covert-channel fallback that base64-reassembles chunks from *.dl.well1.site (tin/tina/ldr/win subdomains), writes the payload to /var/tmp or %TEMP% under a disguised name, chmods it 0755, and detaches-spawns it via /bin/sh -c or cmd.exe. Destination hostnames are assembled at runtime from split string fragments (e.g. ['oob-worker.cf102-baf.wo','rkers.dev'].join('')) to defeat static host-scanning. The package is advertised as reusable cookie module components, and the fetched binary bears no relationship to that stated purpose; publisher identity does not match any of the hardcoded hosts.
Source: amazon-inspector (6c3f53c4d50d2dedd530c65015b26a902950e6e2bbef3cda3560a661d4aad178)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.