-= Per source details. Do not edit below this line.=-
On require() of the package, index.js loads setup.js, which resolves the running platform and architecture, downloads a platform-specific binary from hardcoded Cloudflare Workers endpoints (package-proxy.cf5oobworker.workers.dev, package-proxy.cf8oobworker.workers.dev, package-proxy.cf12oobworker.workers.dev, package-proxy.cf17-ddb.workers.dev, package-proxy.cf25-6eb.workers.dev) and fallback hosts under well1.site (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site) at paths /pkg/package, /pkg/package-arm64, /pkg/loadermac, /pkg/package.exe, writes the fetched bytes to a temp path, chmods 0755, and executes them via childprocess. The sensitive APIs and destination hostnames are reconstructed at runtime through string concatenation and array-join tricks (require("child_"+"process"), os["plat"+"form"], fs["chmod"+"Sync"], hostnames assembled from split fragments) to evade static keyword scanners. Before contacting the remote hosts, setup.js hashes hostname, OS username, cwd, node version, and pid into an install fingerprint and passes it to the transport as an installId, letting the operator track each installer host receiving the payload. Destinations are anonymous Cloudflare Workers subdomains and a lookalike well1.site host, unrelated to any legitimate publisher infrastructure; fetched content is unversioned, unhashed, and unsigned.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-014623",
"import_time": "2026-08-05T09:28:31.702149976Z",
"sha256": "1bcfaaf88e12fe23f911d31199e07bae2134691cb1ae511ca187fa62328f165e",
"modified_time": "2026-08-05T09:17:16Z",
"versions": [
"12.7.1"
],
"source": "amazon-inspector"
},
{
"id": "IN-MAL-2026-014625",
"import_time": "2026-08-05T09:28:31.939411596Z",
"sha256": "34a4b9e0346198bed7019ba0bba4e32036dad95c22d83159b22ab5e9920bd8f0",
"modified_time": "2026-08-05T09:17:33Z",
"versions": [
"7.5.6"
],
"source": "amazon-inspector"
},
{
"id": "IN-MAL-2026-014621",
"import_time": "2026-08-05T09:28:31.455965266Z",
"sha256": "3bf47a8288a6843faf05f01d7b4f27e8389baf2e171130e7f011b95d17dfc04c",
"modified_time": "2026-08-05T09:16:59Z",
"versions": [
"7.5.7"
],
"source": "amazon-inspector"
},
{
"id": "IN-MAL-2026-014624",
"import_time": "2026-08-05T09:28:31.824247208Z",
"sha256": "c0a304d2d0daa291ff873f9036d109f3fd0b7c9e79f446980b70e3435ff04a04",
"modified_time": "2026-08-05T09:17:26Z",
"versions": [
"7.5.8"
],
"source": "amazon-inspector"
},
{
"id": "IN-MAL-2026-014626",
"import_time": "2026-08-05T09:28:32.018950465Z",
"sha256": "edbd819d3b041fefa079889ce29fcd3f55b24e7091f8002b220ee5a593844f79",
"modified_time": "2026-08-05T09:17:42Z",
"versions": [
"7.5.9"
],
"source": "amazon-inspector"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-AE5+4JcIwF4u6N19orS3/HRBinWsWbUD02TZJdpZHYQu0yP/i0qyck1FtdiQPHP8L3JV3Cmdg/VvueCVcmJs6w==",
"sha1": "f8bc4a06a17d2a7d473d4dc269c79450057cf9ac"
},
"filename": "arbocrate-sla-prober-arbocrate-sla-prober-core-12.7.1.tgz"
}
],
"evidence_files": [
{
"sha256": "8f0408a8a36dac6c84b61ce497abe4e97fbec7aa75120b387894e005dff29ac7",
"path": "setup.js",
"tlsh": "17b1a4550afa71384392a1e8d92b5816b09fe5533284e990f34cb6985f97268c3b39fc"
},
{
"path": "index.js",
"sha256": "2898afb10a04efcbb27b5ab98690d71ed252968a0b89fb694ee0d36d097e1625",
"tlsh": "c0f0a94511daa462d9f052a3c9a2c04af92184218ba7219af94d60bb1eb1c14539cff5"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/arbocrate-sla-prober-arbocrate-sla-prober-core/MAL-2026-12140.json"