-= Per source details. Do not edit below this line.=-
On require(), adapter.js fetches a platform-specific binary payload from split-string-obfuscated Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT resolver fallback under *.dl.well1.site (tin.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site). The fetched bytes are written to /var/tmp or %TEMP% under cover-story names (.cache<rand> on POSIX, dotnetdiag<rand>.exe on Windows), chmod 0755'd on POSIX, and spawned detached via /bin/sh or cmd.exe. There is no hash or signature verification of the fetched payload. Endpoint hostnames and resolver domains are reconstructed at runtime by joining literal fragments to evade static string matching. The package presents itself as an observability/metrics bridge, but the shipped behavior on import is download-and-execute of an opaque attacker-controlled binary, giving whoever published this full code execution on any host that installs or imports the package.
{
"malicious-packages-origins": [
{
"versions": [
"20.5.9"
],
"import_time": "2026-08-05T09:28:17.345099983Z",
"sha256": "66329f83c07140aacf28b612ad7211b0279deeef95014e0720b4c7be3097a3fe",
"modified_time": "2026-08-05T08:57:09Z",
"id": "IN-MAL-2026-014484",
"source": "amazon-inspector"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-u0ZXHZtKao0IK1Dtq7rMdlcd23waTUqCkjvKgeDP3RVehqmugTuh+QYEiHoUCX4v1poJUDZySUOmxJjbCBrJ/w==",
"sha1": "4abb0e5140ffc4c53880a853599242c1d20fa31f"
},
"filename": "statist-browser-typed-client-sme.salary.web.metrics-20.5.9.tgz"
}
],
"evidence_files": [
{
"path": "_adapter.js",
"sha256": "91927ffe575b26e9abf880b5fc6893d0fa0ce64c7904452d2e239e60832ff395",
"tlsh": "d9a1b85a066670088b70dbe4cb17441af55bf663378086d0f7aca5985fb613483b2efc"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/statist-browser-typed-client-sme.salary.web.metrics/MAL-2026-12215.json"