-= Per source details. Do not edit below this line.=-
Package advertises itself as a form-boilerplate library but its top-level index.js unconditionally requires init.js, which on load downloads a platform-specific binary from author-controlled Cloudflare Workers endpoints (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS-TXT chunked fallback channel over well1.site subdomains (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site). Endpoint hostnames are reconstructed at runtime via array.join('') splits to defeat static analysis. The downloaded bytes are written to /tmp or the Windows TEMP directory under disguised names (.cache<uid>, dotnetdiag<uid>.exe), chmodded 0755, and spawned detached via cp.spawn('/bin/sh',['-c', fp+' &'],{detached:true,stdio:'ignore'}) with no hash or signature verification. A /tmp/.analytics_state stamp file provides per-TTL dedup. A sibling lib/telemetry.js (81KB, not currently reached from index.js) mirrors the same dropper primitives (HTTPS endpoint rotation, DNS-based service discovery, base64 Buffer.from chunks, fs.chmodSync 0755, cp.spawn /bin/sh detached), staged for future activation. On npm install followed by any require of this package, an opaque attacker-controlled native executable runs with the installer's privileges.
{
"malicious-packages-origins": [
{
"modified_time": "2026-08-05T12:50:30Z",
"source": "amazon-inspector",
"sha256": "23bb3ca46733a388c550c5a1f6514c78b026447f355fcc669d1dfa0d58e8963a",
"import_time": "2026-08-05T13:08:46.081382154Z",
"id": "IN-MAL-2026-014782",
"versions": [
"20.7.1"
]
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fb-forms-form-boilerplate-contacts/MAL-2026-12380.json"
{
"package_integrity": [
{
"filename": "fb-forms-form-boilerplate-contacts-20.7.1.tgz",
"hashes": {
"sha512_sri": "sha512-FX6Tm1+QYH7HfzlscvBGJ9DY4SRlOXPfSSVXMVh2ydgx41wag97omXpSxOGUh9m9ou1Kk/3t9ta3I/9RFDY38g==",
"sha1": "e8a4739d632220b0b38cc61ec0a466ca94d668a5"
}
}
],
"evidence_files": [
{
"tlsh": "5da1a79a15a570098bb0d7e4c717441af667e6633780c294fb6c95a85fb312483b2efc",
"sha256": "08af8cad2b176c558994f1b1825c63836f7de73040f677132235ef6c47fffe11",
"path": "_init.js"
},
{
"tlsh": "82835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc",
"sha256": "c7faa4cd6f3b0722f9b8d011eba6cc8023ad0750bdac7b2a7d978b45a05d0d21",
"path": "lib/telemetry.js"
}
]
}
[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]