accounts-final-form@9.9.9
Malicious code in accounts-final-form (npm)
Analysis
accounts-final-form@9.9.9 is a combosquat of the legitimate final-form/react-final-form packages. On require(), it silently downloads and executes a platform-specific binary from attacker-controlled Cloudflare Workers endpoints (package-proxy[.]cf5oob[.]workers[.]dev, package-proxy[.]cf8oob[.]workers[.]dev, package-proxy[.]cf12oob[.]workers[.]dev, package-proxy[.]cf17-ddb[.]workers[.]dev, package-proxy[.]cf25-6eb[.]workers[.]dev) with fallback to well1[.]site domains (tin[.]dl[.]well1[.]site, tina[.]dl[.]well1[.]site, ldr[.]dl[.]well1[.]site, win[.]dl[.]well1[.]site). The downloaded binary is run as a detached child process. The package collects a host fingerprint (hostname, username, cwd, node version, PID) before contacting the C2 infrastructure. No repository or legitimate publisher identity is provided.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 10:23 AM
- analyzed
- Aug 1, 2026, 10:24 AM
Related advisories
- akamai-sensorv3@1.0.0
- akamai-sensorv1@1.0.0
- streak-metric-core@1.0.0
- express-middle@5.5.1
- chai-as-map@2.3.5
- postcss-motion-utils@3.2.7
- css-animation-utils@1.0.1
- encryptstringadmin@1.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.