LWA-2026-7378 MAL-2026-12211 ↗ confirmed malware

statist-browser-typed-client-mb.product.analytics@20.1.2

Malicious code in statist-browser-typed-client-mb.product.analytics (npm)

Analysis

On require(), the package's _bridge.js fingerprints the OS and architecture, then downloads a platform-specific second-stage binary from one of four Cloudflare Workers C2 endpoints (oob-worker[.]cf100-416[.]workers[.]dev, oob-worker[.]cf99-9b3[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev, oob-worker[.]cf101-adf[.]workers[.]dev) via HTTPS GET /pkg/package (or /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe per platform). If HTTPS fails, it falls back to DNS TXT record chunked exfiltration from c[.]tin[.]dl[.]well1[.]site. The downloaded binary is written to /var/tmp/.cache_<hex> (Linux/macOS) or %TEMP%\dotnet_diag_<hex>.exe (Windows) and executed as a detached background process. A state marker file prevents re-download within ~5.5 hours. The package also includes an 81KB decoy analytics SDK (lib/telemetry.js) to appear legitimate.

analyzed by
Leitwacht
first seen
Aug 2, 2026, 10:11 AM
analyzed
Aug 2, 2026, 10:13 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.