MAL-2026-12215

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/statist-browser-typed-client-sme.salary.web.metrics/MAL-2026-12215.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12215
Published
2026-08-05T08:57:09Z
Modified
2026-08-05T10:06:27.704318933Z
Summary
Malicious code in statist-browser-typed-client-sme.salary.web.metrics (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (66329f83c07140aacf28b612ad7211b0279deeef95014e0720b4c7be3097a3fe)

On require(), adapter.js fetches a platform-specific binary payload from split-string-obfuscated Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT resolver fallback under *.dl.well1.site (tin.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site). The fetched bytes are written to /var/tmp or %TEMP% under cover-story names (.cache<rand> on POSIX, dotnetdiag<rand>.exe on Windows), chmod 0755'd on POSIX, and spawned detached via /bin/sh or cmd.exe. There is no hash or signature verification of the fetched payload. Endpoint hostnames and resolver domains are reconstructed at runtime by joining literal fragments to evade static string matching. The package presents itself as an observability/metrics bridge, but the shipped behavior on import is download-and-execute of an opaque attacker-controlled binary, giving whoever published this full code execution on any host that installs or imports the package.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "20.5.9"
            ],
            "import_time": "2026-08-05T09:28:17.345099983Z",
            "sha256": "66329f83c07140aacf28b612ad7211b0279deeef95014e0720b4c7be3097a3fe",
            "modified_time": "2026-08-05T08:57:09Z",
            "id": "IN-MAL-2026-014484",
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / statist-browser-typed-client-sme.salary.web.metrics

Package

Name
statist-browser-typed-client-sme.salary.web.metrics
View open source insights on deps.dev
Purl
pkg:npm/statist-browser-typed-client-sme.salary.web.metrics

Affected ranges

Affected versions

20.*
20.5.9

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-u0ZXHZtKao0IK1Dtq7rMdlcd23waTUqCkjvKgeDP3RVehqmugTuh+QYEiHoUCX4v1poJUDZySUOmxJjbCBrJ/w==",
                "sha1": "4abb0e5140ffc4c53880a853599242c1d20fa31f"
            },
            "filename": "statist-browser-typed-client-sme.salary.web.metrics-20.5.9.tgz"
        }
    ],
    "evidence_files": [
        {
            "path": "_adapter.js",
            "sha256": "91927ffe575b26e9abf880b5fc6893d0fa0ce64c7904452d2e239e60832ff395",
            "tlsh": "d9a1b85a066670088b70dbe4cb17441af55bf663378086d0f7aca5985fb613483b2efc"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/statist-browser-typed-client-sme.salary.web.metrics/MAL-2026-12215.json"