{"id":"MAL-2026-12053","summary":"Malicious code in tui-react-mobile-styles (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (30d6926a3b8c5bc55e60b4d4f98b2e06fb6c04608bb9442058516814dfb54f1b)\nThe package presents itself as a React Native/mobile UI styles library but at module load time performs a full binary dropper chain. index.js require()s./_shim, which runs an init() at module load that reconstructs destination hostnames from split string fragments to yield oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, and oob-worker.cf100-416.workers.dev, plus a DNS-TXT chunked-base64 fallback path over *.dl.well1.site for environments blocking HTTPS. _shim.js downloads a platform-specific payload, writes it to /var/tmp (or %TEMP%) under cover-story filenames (.cache_\u003chex\u003e on Unix, dotnet_diag_\u003chex\u003e.exe on Windows), chmods it 0755, and spawns it detached via /bin/sh -c \"\u003cpath\u003e &\" or cmd /c start /b. lib/telemetry.js contains the same drop-and-exec primitives (base64 chunk assembly, chmod 0755, detached /bin/sh spawn), with API names split (require(\"child_\" + \"process\"), fs[\"chmod\" + \"Sync\"]) to defeat static analysis. The behavior has no relation to the package's stated UI-styles purpose and grants full-host code execution to whoever controls the Workers endpoints on any machine that installs or requires this package.\n","modified":"2026-08-05T01:49:55.646295033Z","published":"2026-08-05T01:33:55Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-011503","import_time":"2026-08-05T01:39:31.905581422Z","modified_time":"2026-08-05T01:33:55Z","sha256":"30d6926a3b8c5bc55e60b4d4f98b2e06fb6c04608bb9442058516814dfb54f1b","source":"amazon-inspector","versions":["20.8.7"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tui-react-mobile-styles/v/20.8.7"}],"affected":[{"package":{"name":"tui-react-mobile-styles","ecosystem":"npm","purl":"pkg:npm/tui-react-mobile-styles"},"versions":["20.8.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"b01b389003907b76364e551c10359315cba3b7d64812685971b5ac6c6aa5c33a","tlsh":"a1a1a75a166571198b709be886174415f66be6a33780c2d0f79c98884f7613883b2dfc","path":"_shim.js"},{"path":"lib/telemetry.js","sha256":"9d06ed00d7565d44b89c2fef98dec57393f7251f1dc3c280cd24c3b06be8a7ab","tlsh":"5b835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"tui-react-mobile-styles-20.8.7.tgz","hashes":{"sha1":"2f49e46e377f4100737f34c53e66e2b0864c2cea","sha512_sri":"sha512-7UvkzJs9b49KNXuR9juEhJhRE5V6A94jOGGCAom4cQicaTj3Ryd3Qs/wZ7mWd1Qybo4jg5fgYdLr+iBrMwUC7A=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tui-react-mobile-styles/MAL-2026-12053.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}