MAL-2026-12306
Dashboard / Malicious Package / MAL-2026-12306
MAL-2026-12306
Summary: Malicious code in twork-products-taiga2-products-mobile (npm)
Details: Source: amazon-inspector (0870bb9f10cb88f264e25b839c6001a3b2c7d77777115871ba0e3c6f61ddb84b) On require of this package, index.js loads _init.js which selects a platform-specific endpoint, reconstructs destination hostnames at runtime from split-string arrays (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, with a DNS-TXT chunked-base64 fallback under *.dl.well1.site), downloads an opaque native binary over HTTPS, writes it to /tmp or %TEMP% under cover-story names such as.cache_<hex> or dotnet_diag_<hex>.exe, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe with stdio ignored. There is no hash or signature verification. Additional anti-analysis features are present: hostnames are assembled at runtime to evade static string scans, dropped files use benign-looking diagnostic/cache names, a marker file.analytics_state is written, and telemetry-opt-out environment variables (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) are honored as a cover story for the binary drop. The Cloudflare Workers hosts and DNS fallback domains have no relationship to any legitimate publisher of this package.
Affected packages
Package
Name: twork-products-taiga2-products-mobile
Purl: pkg:npm/twork-products-taiga2-products-mobile
Affected ranges
Type: N/A
Events:
