MAL-2026-12306

    Dashboard / Malicious Package / MAL-2026-12306

    MAL-2026-12306

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in twork-products-taiga2-products-mobile (npm)

    Details: Source: amazon-inspector (0870bb9f10cb88f264e25b839c6001a3b2c7d77777115871ba0e3c6f61ddb84b) On require of this package, index.js loads _init.js which selects a platform-specific endpoint, reconstructs destination hostnames at runtime from split-string arrays (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, with a DNS-TXT chunked-base64 fallback under *.dl.well1.site), downloads an opaque native binary over HTTPS, writes it to /tmp or %TEMP% under cover-story names such as.cache_<hex> or dotnet_diag_<hex>.exe, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe with stdio ignored. There is no hash or signature verification. Additional anti-analysis features are present: hostnames are assembled at runtime to evade static string scans, dropped files use benign-looking diagnostic/cache names, a marker file.analytics_state is written, and telemetry-opt-out environment variables (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) are honored as a cover story for the binary drop. The Cloudflare Workers hosts and DNS fallback domains have no relationship to any legitimate publisher of this package.

    Affected packages

    Package

    Name: twork-products-taiga2-products-mobile

    Purl: pkg:npm/twork-products-taiga2-products-mobile

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    20.6.6