travel-core-typings-reducers@20.7.8
Malicious code in travel-core-typings-reducers (npm)
Analysis
On require(), the package loads _ext.js which fingerprints the host platform (OS, architecture, CPU count, memory, hostname) and then downloads a second-stage binary from one of four Cloudflare Workers C2 endpoints (oob-worker[.]cf99-9b3[.]workers[.]dev, oob-worker[.]cf100-416[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev, oob-worker[.]cf101-adf[.]workers[.]dev) over HTTPS. The binary is written to /var/tmp/.cache_<random-hex> (or %TEMP%\dotnet_diag_<hex>.exe on Windows) and spawned as a detached background process. If HTTPS fails, the package falls back to DNS TXT record exfiltration via c[.]tin[.]dl[.]well1[.]site to retrieve the payload. The package has no repository, no README, and no lifecycle scripts — the payload runs immediately on import.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 03:42 PM
- analyzed
- Aug 2, 2026, 03:43 PM
Related advisories
- statist-browser-typed-client-investing.product.loginandauthorization@20.7.3
- pfp-forms-insurance-health@20.2.2
- fry-page-maker-types@20.6.4
- statist-browser-typed-client-itsa.digitalinterview.events@20.8.2
- tinkoff-pfp-block-mobile-advert-footer@20.3.3
- tinkoff-statist-browser-typed-client-sme.compliance.web.events@20.4.4
- statist-browser-typed-client-social.shorts.editor@20.7.1
- pfp-forms-sme-sitebuilder@20.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.