accounts-timeline@9.6.10
Malicious code in accounts-timeline (npm)
Analysis
On require(), accounts-timeline silently downloads and executes a platform-specific binary from Cloudflare Workers subdomains (oob-worker[.]cf with subdomains 99-9b3[.]workers[.]dev through 103-070[.]workers[.]dev) with fallback DNS resolvers at tin[.]dl[.]well1[.]site, tina[.]dl[.]well1[.]site, ldr[.]dl[.]well1[.]site, and win[.]dl[.]well1[.]site. The binary is fetched via HTTPS, written to /var/tmp (or C:\Windows\Temp on Windows) with a random filename, made executable, spawned as a detached background process via child_process.execFile, and then deleted after 5 seconds. The package collects a host fingerprint (hostname, username, cwd, Node.js version, PID) before downloading. Supported platforms: linux/x64, linux/arm64, darwin, win32.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 11:16 AM
- analyzed
- Aug 1, 2026, 11:19 AM
- weekly installs
- 115
Related advisories
- a.poltoradnev-package-c@6.1.10
- warp-drive-internal-tooling@99.9.9
- mcp-audit-sync-internal@99.9.9
- native-hello-plugin@1.2.0
- streak-metric-core@1.0.0
- react-fast-refresh-helper@1.2.6
- express-middle@5.5.1
- streak-cal-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.