LWA-2026-7317 MAL-2026-12137 ↗ confirmed malware

accounts-timeline@9.6.10

Malicious code in accounts-timeline (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1204.002 · Malicious File

Analysis

On require(), accounts-timeline silently downloads and executes a platform-specific binary from Cloudflare Workers subdomains (oob-worker[.]cf with subdomains 99-9b3[.]workers[.]dev through 103-070[.]workers[.]dev) with fallback DNS resolvers at tin[.]dl[.]well1[.]site, tina[.]dl[.]well1[.]site, ldr[.]dl[.]well1[.]site, and win[.]dl[.]well1[.]site. The binary is fetched via HTTPS, written to /var/tmp (or C:\Windows\Temp on Windows) with a random filename, made executable, spawned as a detached background process via child_process.execFile, and then deleted after 5 seconds. The package collects a host fingerprint (hostname, username, cwd, Node.js version, PID) before downloading. Supported platforms: linux/x64, linux/arm64, darwin, win32.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 11:16 AM
analyzed
Aug 1, 2026, 11:19 AM
weekly installs
115

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.