Malicious code in hubert-appointment-v2-task-create-am (npm)
The npm package hubert-appointment-v2-task-create-am contained malicious code that downloads and executes unsigned platform-specific binaries from attacker-controlled Cloudflare Workers domains on module load. The malicious payload is disguised as telemetry/analytics functionality.
- Disclosed
- Last updated
- Blast radius
- All users of hubert-appointment-v2-task-create-am npm package
- Ecosystems
- Attack vectors
- Affected entities
- hubert-appointment-v2-task-create-amnpm package containing malicious code
The npm package hubert-appointment-v2-task-create-am was found to contain malicious code in its platform.js module. Upon require(), the code reconstructs hostnames from obfuscated string arrays and downloads unsigned, platform-specific binaries from attacker-controlled Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS-TXT base64 fallback mechanism through *.dl.well1.site domains.\n\nThe downloaded binary is written to /var/tmp/.cache on Linux or to the Windows TEMP directory as dotnet_diag_.exe, given execute permissions (0755), and spawned detached via shell commands. The malicious activity is disguised as telemetry/analytics functionality with a DO_NOT_TRACK opt-out and cooldown marker to evade detection.\n\nNo cryptographic verification (hash or signature) is performed on the fetched binaries, allowing arbitrary code execution on affected systems. The incident was identified by the OpenSSF malicious-packages project and published via GitHub Security Advisory GHSA-62xx-7cqv-qp4g.
Indicators of compromise
- Packages
- hubert-appointment-v2-task-create-am
- Domains
- oob-worker.cf101-adf.workers.dev
- oob-worker.cf102-baf.workers.dev
- oob-worker.cf103-070.workers.dev
- tin.dl.well1.site
Remediation
- Immediately remove or uninstall the hubert-appointment-v2-task-create-am package from all affected systems
- Audit systems that had this package installed for signs of unauthorized binary execution or network connections to the identified Cloudflare Workers domains
- Block outbound connections to *.workers.dev and *.dl.well1.site at the network level
- Review package dependencies to ensure no other packages depend on hubert-appointment-v2-task-create-am
- Implement package integrity verification and supply chain security scanning in your npm dependency management
Sources
- GitHub Advisory GHSA-62xx-7cqv-qp4g · GitHub Advisory Database
Cite this entry
"Malicious code in hubert-appointment-v2-task-create-am (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 5, 2026; last updated August 5, 2026. https://supplychainattack.org/incident/malicious-code-in-hubert-appointment-v2-task-create-am-npm-pz42qs
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in a.poltoradnev-package-a
The npm package a.poltoradnev-package-a contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in @zynkit/probe
Malware discovered in the npm package @zynkit/probe. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in awesome-ts-jest
Malware was discovered in the npm package awesome-ts-jest. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in async-mutex-v2
Malware was discovered in the npm package async-mutex-v2. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.
npmCompromised package