arbocrate-sla-prober-arbocrate-sla-prober-core@7.5.8
Malicious code in arbocrate-sla-prober-arbocrate-sla-prober-core (npm)
Analysis
On require(), the package auto-executes a setup routine that fingerprints the host (hostname, username, cwd, Node.js version, PID) and detects the platform (Linux x64/arm64, macOS, Windows). It then connects to attacker-controlled hosts (oob-worker[.]cf, well1[.]site) to download a platform-specific binary, writes it to /var/tmp (or C:\Windows\Temp on Windows), makes it executable, and spawns it as a detached child process. The binary download is wrapped inside a large analytics-SDK facade (lib/telemetry.js) that provides HTTPS transport, endpoint rotation, and DNS-based failover to multiple CDN nodes. The package has no lifecycle hooks — execution happens on require() via process.nextTick.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 11:23 AM
- analyzed
- Aug 1, 2026, 11:28 AM
- weekly installs
- 108
Related advisories
- afisha-storybook-default@9.7.10
- beaver-ui-card-large@9.6.3
- accounts-loading-state@8.9.4
- bcore-bravo-eslint-config@9.5.7
- accounts-timeline@9.6.10
- a.poltoradnev-package-c@6.1.10
- warp-drive-internal-tooling@99.9.9
- mcp-audit-sync-internal@99.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.