Malicious code in damir-cbr-dawdntrnssbf (npm)
The npm package damir-cbr-dawdntrnssbf contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package uses obfuscated C2 hostnames and DNS TXT-record fallback channels to evade detection.
- Disclosed
- Last updated
- Blast radius
- Any developer or application that installed damir-cbr-dawdntrnssbf from npm
- Ecosystems
- Attack vectors
- Affected entities
- damir-cbr-dawdntrnssbfnpm package containing malicious code
The npm package damir-cbr-dawdntrnssbf was found to contain malicious code that executes upon require(). The _polyfill.js module downloads platform-specific binaries from attacker-controlled Cloudflare Workers hosts (oob-worker.cf10x-*.workers.dev) and uses a DNS TXT-record chunked-base64 fallback channel via *.dl.wel1.ru when HTTPS egress is blocked.
The malicious behavior writes the downloaded binary to hidden paths (/tmp/.cache_ on Unix, %TEMP%\dotnet_diag_.exe on Windows), sets executable permissions (0755), and spawns it detached through /bin/sh or cmd.exe. The C2 hostnames are reconstructed at runtime by joining split string fragments to evade static detection.
The fetched binaries are opaque, unversioned, and unpinned by hash, originating from non-publisher infrastructure. The malicious activity is framed as telemetry or analytics functionality. The incident was identified by the OpenSSF malicious-packages project and reported via GitHub Security Advisory GHSA-j2fq-fmwf-wh5r.
Indicators of compromise
- Packages
- damir-cbr-dawdntrnssbf
- Domains
- oob-worker.cf10x-*.workers.dev
- *.dl.wel1.ru
Remediation
- Remove damir-cbr-dawdntrnssbf from all projects immediately
- Audit package.json and lock files for any presence of this package
- Review application logs and system activity for evidence of binary downloads from oob-worker.cf10x-*.workers.dev or *.dl.wel1.ru
- Check for unexpected processes spawned from /bin/sh or cmd.exe, and suspicious files in /tmp/.cache_ (Unix) or %TEMP%\dotnet_diag_.exe (Windows)
- Regenerate any credentials or secrets that may have been exposed on affected systems
- Monitor for any C2 communication to the attacker-controlled infrastructure
Sources
- GitHub Advisory GHSA-j2fq-fmwf-wh5r · GitHub Advisory Database
Cite this entry
"Malicious code in damir-cbr-dawdntrnssbf (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 7, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-damir-cbr-dawdntrnssbf-npm-35qjgy
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in userbotjs-jun
The npm package userbotjs-jun was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in rendezvous-js
The npm package rendezvous-js contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in autoai
The npm package autoai was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.
npmCompromised package - containedcritical
Malware in a.poltoradnev-package-c
Malware was discovered in the npm package a.poltoradnev-package-c. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package