MAL-2026-12140

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/arbocrate-sla-prober-arbocrate-sla-prober-core/MAL-2026-12140.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12140
Published
2026-08-05T09:16:59Z
Modified
2026-08-05T10:05:48.004600531Z
Summary
Malicious code in arbocrate-sla-prober-arbocrate-sla-prober-core (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (34a4b9e0346198bed7019ba0bba4e32036dad95c22d83159b22ab5e9920bd8f0)

On require() of the package, index.js loads setup.js, which resolves the running platform and architecture, downloads a platform-specific binary from hardcoded Cloudflare Workers endpoints (package-proxy.cf5oobworker.workers.dev, package-proxy.cf8oobworker.workers.dev, package-proxy.cf12oobworker.workers.dev, package-proxy.cf17-ddb.workers.dev, package-proxy.cf25-6eb.workers.dev) and fallback hosts under well1.site (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site) at paths /pkg/package, /pkg/package-arm64, /pkg/loadermac, /pkg/package.exe, writes the fetched bytes to a temp path, chmods 0755, and executes them via childprocess. The sensitive APIs and destination hostnames are reconstructed at runtime through string concatenation and array-join tricks (require("child_"+"process"), os["plat"+"form"], fs["chmod"+"Sync"], hostnames assembled from split fragments) to evade static keyword scanners. Before contacting the remote hosts, setup.js hashes hostname, OS username, cwd, node version, and pid into an install fingerprint and passes it to the transport as an installId, letting the operator track each installer host receiving the payload. Destinations are anonymous Cloudflare Workers subdomains and a lookalike well1.site host, unrelated to any legitimate publisher infrastructure; fetched content is unversioned, unhashed, and unsigned.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-014623",
            "import_time": "2026-08-05T09:28:31.702149976Z",
            "sha256": "1bcfaaf88e12fe23f911d31199e07bae2134691cb1ae511ca187fa62328f165e",
            "modified_time": "2026-08-05T09:17:16Z",
            "versions": [
                "12.7.1"
            ],
            "source": "amazon-inspector"
        },
        {
            "id": "IN-MAL-2026-014625",
            "import_time": "2026-08-05T09:28:31.939411596Z",
            "sha256": "34a4b9e0346198bed7019ba0bba4e32036dad95c22d83159b22ab5e9920bd8f0",
            "modified_time": "2026-08-05T09:17:33Z",
            "versions": [
                "7.5.6"
            ],
            "source": "amazon-inspector"
        },
        {
            "id": "IN-MAL-2026-014621",
            "import_time": "2026-08-05T09:28:31.455965266Z",
            "sha256": "3bf47a8288a6843faf05f01d7b4f27e8389baf2e171130e7f011b95d17dfc04c",
            "modified_time": "2026-08-05T09:16:59Z",
            "versions": [
                "7.5.7"
            ],
            "source": "amazon-inspector"
        },
        {
            "id": "IN-MAL-2026-014624",
            "import_time": "2026-08-05T09:28:31.824247208Z",
            "sha256": "c0a304d2d0daa291ff873f9036d109f3fd0b7c9e79f446980b70e3435ff04a04",
            "modified_time": "2026-08-05T09:17:26Z",
            "versions": [
                "7.5.8"
            ],
            "source": "amazon-inspector"
        },
        {
            "id": "IN-MAL-2026-014626",
            "import_time": "2026-08-05T09:28:32.018950465Z",
            "sha256": "edbd819d3b041fefa079889ce29fcd3f55b24e7091f8002b220ee5a593844f79",
            "modified_time": "2026-08-05T09:17:42Z",
            "versions": [
                "7.5.9"
            ],
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / arbocrate-sla-prober-arbocrate-sla-prober-core

Package

Name
arbocrate-sla-prober-arbocrate-sla-prober-core
View open source insights on deps.dev
Purl
pkg:npm/arbocrate-sla-prober-arbocrate-sla-prober-core

Affected ranges

Affected versions

7.*
7.5.6
7.5.7
7.5.8
7.5.9
12.*
12.7.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-AE5+4JcIwF4u6N19orS3/HRBinWsWbUD02TZJdpZHYQu0yP/i0qyck1FtdiQPHP8L3JV3Cmdg/VvueCVcmJs6w==",
                "sha1": "f8bc4a06a17d2a7d473d4dc269c79450057cf9ac"
            },
            "filename": "arbocrate-sla-prober-arbocrate-sla-prober-core-12.7.1.tgz"
        }
    ],
    "evidence_files": [
        {
            "sha256": "8f0408a8a36dac6c84b61ce497abe4e97fbec7aa75120b387894e005dff29ac7",
            "path": "setup.js",
            "tlsh": "17b1a4550afa71384392a1e8d92b5816b09fe5533284e990f34cb6985f97268c3b39fc"
        },
        {
            "path": "index.js",
            "sha256": "2898afb10a04efcbb27b5ab98690d71ed252968a0b89fb694ee0d36d097e1625",
            "tlsh": "c0f0a94511daa462d9f052a3c9a2c04af92184218ba7219af94d60bb1eb1c14539cff5"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/arbocrate-sla-prober-arbocrate-sla-prober-core/MAL-2026-12140.json"