accounts-loading-state@8.9.4
Malicious code in accounts-loading-state (npm)
Analysis
accounts-loading-state@8.9.4 is a remote binary downloader disguised as a microservice utility. On require, it collects a host fingerprint (hostname, username, cwd, Node.js version, PID) and downloads a platform-specific binary from Cloudflare Workers-based C2 infrastructure (oob-worker[.]cf subdomains on workers[.]dev, with well1[.]site as fallback). The binary is written to /var/tmp (or %TEMP% on Windows), made executable, and spawned as a detached process that outlives the parent. Platform-specific download paths: /pkg/package (linux x64), /pkg/package-arm64 (linux arm64), /pkg/loader_mac (macOS), /pkg/package.exe (Windows). The C2 domains are constructed from split strings to evade static detection.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 11:15 AM
- analyzed
- Aug 1, 2026, 11:20 AM
- weekly installs
- 112
Related advisories
- bcore-bravo-eslint-config@9.5.7
- accounts-timeline@9.6.10
- a.poltoradnev-package-c@6.1.10
- warp-drive-internal-tooling@99.9.9
- mcp-audit-sync-internal@99.9.9
- native-hello-plugin@1.2.0
- streak-metric-core@1.0.0
- react-fast-refresh-helper@1.2.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.