LWA-2026-7321 MAL-2026-12140 ↗ confirmed malware

arbocrate-sla-prober-arbocrate-sla-prober-core@7.5.8

Malicious code in arbocrate-sla-prober-arbocrate-sla-prober-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1204.002 · Malicious File

Analysis

On require(), the package auto-executes a setup routine that fingerprints the host (hostname, username, cwd, Node.js version, PID) and detects the platform (Linux x64/arm64, macOS, Windows). It then connects to attacker-controlled hosts (oob-worker[.]cf, well1[.]site) to download a platform-specific binary, writes it to /var/tmp (or C:\Windows\Temp on Windows), makes it executable, and spawns it as a detached child process. The binary download is wrapped inside a large analytics-SDK facade (lib/telemetry.js) that provides HTTPS transport, endpoint rotation, and DNS-based failover to multiple CDN nodes. The package has no lifecycle hooks — execution happens on require() via process.nextTick.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 11:23 AM
analyzed
Aug 1, 2026, 11:28 AM
weekly installs
108

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.