Logo
npm

twork-data-services-aggregator-company-sme-main-timeline-loader-with-customers@20.3.8

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-12287

Ecosystem

npm

Summary

On require(), index.js loads _bridge.js which assembles obfuscated Cloudflare Workers hostnames from split string literals (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev) and downloads a platform-specific opaque binary via https.get. If HTTPS fails, a DNS-TXT covert-channel fallback queries c.<domain> for a chunk count then <i>.<domain> TXT records under tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site, base64-decoding the concatenated chunks. The bytes are written to a hidden path in /tmp or %TEMP%, chmodded 0755, and executed detached via spawn("/bin/sh", ["-c", fp+" &"]) or spawn("cmd",...). Cover strings such as "analytics_state" and "dotnet_diag" mask the behavior. The hosts are unrelated to any declared publisher, the fetched content is opaque and unverified, and execution fires automatically when any consumer imports the package.

Source: amazon-inspector (401d167bfbb3ec350a033f908aef6678495563e92c6b090d0eaab85bd1c2b7ba)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.