Logo
npm

tms-x-headers@20.2.9

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-12480

Ecosystem

npm

Summary

On require() of the package, _helpers.js fetches a platform-specific binary from hostnames assembled by concatenating string fragments (oob-worker.cf101-adf.workers.dev and sibling cf103-070 / cf100-416 workers.dev hosts), with a DNS-TXT fallback channel resolved through fragment-joined *.dl.well1.site names. The fetched bytes are written to a temp file with a cover-story name (dotnet_diag_<hex>.exe on Windows,.cache_<hex> on Unix), chmod 0755, and spawned detached via cmd.exe /c start or /bin/sh -c with no hash or signature verification. The child_process module is also required via a split string ("child_" + "process") in lib/telemetry.js. The destination hosts are not the package publisher, are deliberately fragmented to evade static string matching, and the temp filename mimics legitimate.NET diagnostics tooling. Installing or loading the package therefore runs attacker-controlled native code on the installer's host.

Source: amazon-inspector (2d2d5c1a35629a169457029c69505622c3f6a7b6bdc8958480aea47ffe08266b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.