LWA-2026-7315 MAL-2026-11504 ↗ confirmed malware

accounts-final-form@9.9.9

Malicious code in accounts-final-form (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

accounts-final-form@9.9.9 is a combosquat of the legitimate final-form/react-final-form packages. On require(), it silently downloads and executes a platform-specific binary from attacker-controlled Cloudflare Workers endpoints (package-proxy[.]cf5oob[.]workers[.]dev, package-proxy[.]cf8oob[.]workers[.]dev, package-proxy[.]cf12oob[.]workers[.]dev, package-proxy[.]cf17-ddb[.]workers[.]dev, package-proxy[.]cf25-6eb[.]workers[.]dev) with fallback to well1[.]site domains (tin[.]dl[.]well1[.]site, tina[.]dl[.]well1[.]site, ldr[.]dl[.]well1[.]site, win[.]dl[.]well1[.]site). The downloaded binary is run as a detached child process. The package collects a host fingerprint (hostname, username, cwd, node version, PID) before contacting the C2 infrastructure. No repository or legitimate publisher identity is provided.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 10:23 AM
analyzed
Aug 1, 2026, 10:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.