MAL-2026-12215

    Dashboard / Malicious Package / MAL-2026-12215

    MAL-2026-12215

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in statist-browser-typed-client-sme.salary.web.metrics (npm)

    Details: Source: amazon-inspector (66329f83c07140aacf28b612ad7211b0279deeef95014e0720b4c7be3097a3fe) On require(), _adapter.js fetches a platform-specific binary payload from split-string-obfuscated Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT resolver fallback under *.dl.well1.site (tin.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site). The fetched bytes are written to /var/tmp or %TEMP% under cover-story names (.cache_<rand> on POSIX, dotnet_diag_<rand>.exe on Windows), chmod 0755'd on POSIX, and spawned detached via /bin/sh or cmd.exe. There is no hash or signature verification of the fetched payload. Endpoint hostnames and resolver domains are reconstructed at runtime by joining literal fragments to evade static string matching. The package presents itself as an observability/metrics bridge, but the shipped behavior on import is download-and-execute of an opaque attacker-controlled binary, giving whoever published this full code execution on any host that installs or imports the package.

    Affected packages

    Package

    Name: statist-browser-typed-client-sme.salary.web.metrics

    Purl: pkg:npm/statist-browser-typed-client-sme.salary.web.metrics

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    20.5.9
    MAL-2026-12215 | CVE-DB