{"id":"MAL-2026-12290","summary":"Malicious code in twork-data-services-customer-api-v2-customer-vip-status (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bd6182daf75450f1e553f81c3979a275c481690e27d04712285b85a25ebadc3b)\nOn require of this package, index.js loads _platform.js which selects a platform-specific payload (linux_x64/linux_arm64/darwin/win32), downloads an opaque binary over HTTPS from a pool of *.workers.dev hosts, writes it to /var/tmp/.cache_\u003chex\u003e or %TEMP%/dotnet_diag_\u003chex\u003e.exe, chmods it 0755, and spawns it detached via /bin/sh or cmd with unref, so execution survives the parent process. Destination hostnames are not stored as plain literals — they are assembled at runtime from split fragments (e.g. ['oob-worker.cf101-a','df.worke','rs.d','ev'].join('')) to evade string scans. If HTTPS retrieval fails, the code falls back to DNS TXT lookups against numbered subdomains of dl.well1.site and reassembles a base64-encoded binary from the concatenated TXT records, bypassing HTTPS egress inspection. The disguised on-disk filenames (dotnet_diag_*,.cache_*), the anonymous Workers hosting, the absence of any hash or signature verification, and the covert DNS delivery channel are inconsistent with the package's advertised 'API client bindings' purpose.\n","modified":"2026-08-05T10:07:02.572078416Z","published":"2026-08-05T09:13:18Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T09:13:18Z","sha256":"bd6182daf75450f1e553f81c3979a275c481690e27d04712285b85a25ebadc3b","source":"amazon-inspector","versions":["20.9.7"],"id":"IN-MAL-2026-014595","import_time":"2026-08-05T09:28:28.817626752Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/twork-data-services-customer-api-v2-customer-vip-status/v/20.9.7"}],"affected":[{"package":{"name":"twork-data-services-customer-api-v2-customer-vip-status","ecosystem":"npm","purl":"pkg:npm/twork-data-services-customer-api-v2-customer-vip-status"},"versions":["20.9.7"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"f37ca6ece7f85dc15a9ac7e71e808cc7c5d56391fcb2627af61a91b4d565a0c3","tlsh":"f5a1955a16a9701c8bb0abe087174415f65bf2533391c294fb5ca9945fb312483b2efc","path":"_platform.js"}],"package_integrity":[{"filename":"twork-data-services-customer-api-v2-customer-vip-status-20.9.7.tgz","hashes":{"sha1":"e0f3a7e987ab2cd615b5a90b84162c711457a876","sha512_sri":"sha512-OAZMCyNwDuQs8u7h2+2p45PQnDMpMFI5IM0roEnD/a+ejaBcVLAK0AVB4aPZ27GJeEOuqFTbnpkxwVvSdfPNbQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/twork-data-services-customer-api-v2-customer-vip-status/MAL-2026-12290.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}