{"id":"MAL-2026-12309","summary":"Malicious code in statist-browser-typed-client-jumptaxi.feature.contacts (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (534768cd8d709ca1a5701f182e4e509713821923b6995a2bb868d79b0fdded62)\nOn require of the package (index.js loads./_vendor at import), _vendor.js selects a platform-specific staging path, downloads a binary from a rotated list of Cloudflare workers.dev origins whose hostnames are reconstructed at runtime from split-string arrays joined together, with a DNS TXT covert-channel fallback that reassembles base64 chunks from numbered subdomains under dl.well1.site. The fetched bytes are written to /var/tmp or %TEMP% under cover-story filenames (.cache_\u003crand\u003e, dotnet_diag_\u003crand\u003e.exe,.analytics_state), chmod 0755, and spawned detached via /bin/sh -c or cmd.exe /c start. No hash or signature verification is performed and destinations are not first-party publisher infrastructure. Any consumer that imports this package auto-executes an attacker-controlled native payload on the installer's host.\n","modified":"2026-08-05T12:34:50.228985429Z","published":"2026-08-05T12:13:59Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T12:13:59Z","sha256":"534768cd8d709ca1a5701f182e4e509713821923b6995a2bb868d79b0fdded62","source":"amazon-inspector","versions":["20.7.7"],"id":"IN-MAL-2026-014631","import_time":"2026-08-05T12:15:14.312221787Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/statist-browser-typed-client-jumptaxi.feature.contacts/v/20.7.7"}],"affected":[{"package":{"name":"statist-browser-typed-client-jumptaxi.feature.contacts","ecosystem":"npm","purl":"pkg:npm/statist-browser-typed-client-jumptaxi.feature.contacts"},"versions":["20.7.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"d0637b335fff50cff0449bfe8abd9b2d8bd28a222b380aea2f5b4437e80af29e","tlsh":"60a1b79a026670184bb0dbe4cb1b8826f55bf65377808684f79ca5885f7302483f1efc","path":"_vendor.js"}],"package_integrity":[{"filename":"statist-browser-typed-client-jumptaxi.feature.contacts-20.7.7.tgz","hashes":{"sha1":"9c4eb8f77a48a4fdbc25b37923e75c2a919bd7df","sha512_sri":"sha512-3XQtqBm2BPx+KKXASMSDM9O6NPmmkKTX20D5Roo/MxEj631nyjwN7rz8vSDb/KMFwIc2f0dTIU6YY2AKC8qzaw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/statist-browser-typed-client-jumptaxi.feature.contacts/MAL-2026-12309.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}