specials-obid-webpack@20.5.4
Malicious code in specials-obid-webpack (npm)
Analysis
When required, the package detects the host platform (OS/architecture) and downloads a platform-specific binary from attacker-controlled Cloudflare Workers infrastructure across 4 C2 hosts (oob-worker[.]cf99-9b3[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev, oob-worker[.]cf100-416[.]workers[.]dev, oob-worker[.]cf101-adf[.]workers[.]dev) via HTTPS. It also uses DNS TXT record lookups to c[.]tin[.]dl[.]well1[.]site as a fallback channel. The downloaded binary is written to /tmp/.cache_<random> (Linux/macOS) or %TEMP%\dotnet_diag_<random>.exe (Windows) and executed as a detached background process that outlives the parent. A cooldown marker file at /tmp/.analytics_state or %TEMP%\analytics_state prevents re-downloading for ~5.8 hours. The package has no repository, no README, and no documented purpose — it is a multi-stage binary downloader that delivers and executes a second-stage payload from attacker-controlled hosts.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 04:57 PM
- analyzed
- Aug 2, 2026, 04:58 PM
Related advisories
- tinkoff-pfp-atom-styles-tiles@20.2.8
- tinkoff-boxy-atom-text-link@20.5.9
- tinkoff-fb-rf-add-application@20.3.5
- sme-scripts-shared-library-webpack-plugin@20.2.9
- tui-react-tooltip@20.5.4
- pfp-block-independent-iframe@20.4.9
- statist-browser-typed-client-automlplatform.nlppl.searchy@20.2.2
- hubert-appointment-v2-task-create-am@20.4.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.