twork-data-services-sme-operations-authorizations @20.8.9
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12302
Ecosystem
npm
Summary
On require of the package, index.js loads _compat.js which fetches a platform-specific binary from hostnames assembled by array-join to hide them from static scanners (oob-worker.cf102-baf.workers.dev, cf100-416.workers.dev, cf103-070.workers.dev, cf99-9b3.workers.dev), with a DNS TXT base64 chunked fallback via *.dl.well1.site resolvers. The fetched bytes are written to /var/tmp or %TEMP% under a disguised name (.cache_<hex> on Unix, dotnet_diag_<hex>.exe on Windows), chmodded to 0755, and spawned detached via /bin/sh -c "<path> &" or cmd.exe /c start. No hash or signature verification is performed on the downloaded binary. A parallel dropper implementation in lib/telemetry.js uses the same pattern (child_process required via string concatenation, chmodSync accessed via computed property name, base64-decoded payload buffer, detached shell spawn). The package declares no legitimate purpose that would justify fetching and executing an unsigned remote binary at import time.
Source: amazon-inspector (d73622aa5b1b1b3f39f914022e80a8429b948186033c2e98d5f5610e93129612)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.