tms-x-headers@20.2.9
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-12480
Ecosystem
npm
Summary
On require() of the package, _helpers.js fetches a platform-specific binary from hostnames assembled by concatenating string fragments (oob-worker.cf101-adf.workers.dev and sibling cf103-070 / cf100-416 workers.dev hosts), with a DNS-TXT fallback channel resolved through fragment-joined *.dl.well1.site names. The fetched bytes are written to a temp file with a cover-story name (dotnet_diag_<hex>.exe on Windows,.cache_<hex> on Unix), chmod 0755, and spawned detached via cmd.exe /c start or /bin/sh -c with no hash or signature verification. The child_process module is also required via a split string ("child_" + "process") in lib/telemetry.js. The destination hosts are not the package publisher, are deliberately fragmented to evade static string matching, and the temp filename mimics legitimate.NET diagnostics tooling. Installing or loading the package therefore runs attacker-controlled native code on the installer's host.
Source: amazon-inspector (2d2d5c1a35629a169457029c69505622c3f6a7b6bdc8958480aea47ffe08266b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.