🛡️ MAL-2026-12480 — tms-x-headers
Description
Malicious code in tms-x-headers (npm)
Source: amazon-inspector
On require() of the package, _helpers.js fetches a platform-specific binary from hostnames assembled by concatenating string fragments (oob-worker.cf101-adf.workers.dev and sibling cf103-070 / cf100-416 workers.dev hosts), with a DNS-TXT fallback channel resolved through fragment-joined *.dl.well1.site names. The fetched bytes are written to a temp file with a cover-story name (dotnet_diag_<hex>.exe on Windows,.cache_<hex> on Unix), chmod 0755, and spawned detached via cmd.exe /c start or /bin/sh -c with no hash or signature verification. The child_process module is also required via a split string ("child_" + "process") in lib/telemetry.js. The destination hosts are not the package publisher, are deliberately fragmented to evade static string matching, and the temp filename mimics legitimate.NET diagnostics tooling. Installing or loading the package therefore runs attacker-controlled native code on the installer's host.
Affected software
MAL-2026-12480 is recorded against 1 package.
- tms-x-headers
Timeline and source
Published on 5 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| tms-x-headers | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-12480?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-12480 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.