MAL-2026-12179
Dashboard / Malicious Package / MAL-2026-12179
MAL-2026-12179
Summary: Malicious code in fb-insurance--boxified-form-vzr-test (npm)
Details: Source: amazon-inspector (a1527da37d48efd3c216bf62d4f3d167181948006ad5d8e88f2ff9fa40eb0875) On require of the package, index.js loads _loader.js which selects a platform-specific endpoint, fetches an executable payload over HTTPS from hardcoded Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, cf100-416.workers.dev, cf103-070.workers.dev), writes it to /var/tmp or %TEMP% under a deceptive filename (`.cache_<hex>` on POSIX, `dotnet_diag_<hex>.exe` on Windows), chmods it 0755, and spawns it detached-and-unref'd via `/bin/sh -c` or `cmd`. If the HTTPS mirrors fail, _loader.js falls back to a DNS-TXT covert channel: it resolves `c.<domain>` for a chunk count against resolvers under *.dl.well1.site (tin/tina/ldr/win subdomains) and reassembles N base64 TXT fragments from `<i>.<domain>` into the same executable buffer. Destination hostnames and resolver domains are constructed at runtime by joining short substring arrays (e.g. ['oob-worker.cf99-9b3','.worker','s.dev'].join('')) to evade static string matching. No hash or signature is verified on the fetched bytes. The fetched executable runs with the installer's privileges.
Affected packages
Package
Name: fb-insurance--boxified-form-vzr-test
Purl: pkg:npm/fb-insurance--boxified-form-vzr-test
Affected ranges
Type: N/A
Events:
