OpenSSF/OSV advisory MAL-2026-12295 confirms this npm version as malicious. On require of the package's main index.js, _support.js reconstructs attacker-controlled hostnames from string-split arrays (oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT fallback under dl.well1.site (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site), downloads a platform-specific binary over HTTPS, writes it to...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in twork-data-services-procedure-engine-api-v1-procedure-info (npm)
Details
On require of the package's main index.js, _support.js reconstructs attacker-controlled hostnames from string-split arrays (oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT fallback under dl.well1.site (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site), downloads a platform-specific binary over HTTPS, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%/dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd. No hash or signature verification is performed. Filenames and lock paths (analytics_state, dotnet_diag_*.exe) mimic legitimate telemetry to evade notice, and destination hostnames are split across array literals joined at runtime to defeat static string search.
Decision reason
OpenSSF Malicious Packages via OSV confirms twork-data-services-procedure-engine-api-v1-procedure-info@20.6.9 as malicious (MAL-2026-12295): Malicious code in twork-data-services-procedure-engine-api-v1-procedure-info (npm)