Logo
npm

statist-browser-typed-client-mb.product.analytics@20.1.2

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC

Malicious

OSV ID

MAL-2026-12211

Ecosystem

npm

Summary

On require() of the package, index.js loads _bridge.js which detects the host platform, fetches a native binary from a rotating list of hardcoded Cloudflare workers.dev endpoints (with a DNS-TXT chunked base64 fallback via well1.site subdomains), writes it to /tmp or %TEMP% under a masquerading name such as dotnet_diag_<hex>.exe or.cache_<hex>, chmods 0755, and spawns it detached via cmd.exe or /bin/sh. The C2 hostnames and payload paths are assembled at runtime through array-join string-splitting to evade static analysis, and the require of _bridge.js is wrapped in a try/catch that silently swallows errors. No hash or signature verification is performed on the downloaded binary. The result is full-host remote code execution on any machine that installs or requires this package.

Source: amazon-inspector (846c740775556f5a2d302684c1bc3f5d39aea88a5208b98a2730c3ffff1308e7)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.