{"id":"MAL-2026-11538","summary":"Malicious code in eacq-payform-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ac90938ceb191a40f640c12f11258ef8a518d24480072eeaa0791a155a49c724)\nOn require() of the package, index.js loads _vendor.js which selects a platform-specific endpoint, fetches an opaque binary over HTTPS from Cloudflare Workers subdomains whose hostnames are reconstructed at runtime by joining split string fragments (e.g. \"oob-worker.cf102-ba\"+\"f.w\"+\"orkers.dev\"), with a DNS TXT chunked-base64 fallback channel (c.\u003cdomain\u003e for chunk count, then N.\u003cdomain\u003e TXT queries reassembled via Buffer.from(parts.join(\"\"), \"base64\")). The fetched bytes are written under a disguised name (dot-file or dotnet_diag masquerade) in /var/tmp or %TEMP%, chmod 0o755 on POSIX, then detached-spawned via /bin/sh -c or cmd.exe. Package advertises itself only as a 'platform core' with no legitimate need for platform-detected binary execution. Host strings are deliberately fragmented to evade static analysis; a rate-limit marker is written to /tmp/.analytics_state or %TEMP%\\analytics_state.\n","modified":"2026-08-04T23:05:02.859450981Z","published":"2026-08-04T22:08:17Z","database_specific":{"malicious-packages-origins":[{"versions":["20.3.6"],"id":"IN-MAL-2026-011346","import_time":"2026-08-04T22:30:11.954600636Z","modified_time":"2026-08-04T22:08:17Z","sha256":"ac90938ceb191a40f640c12f11258ef8a518d24480072eeaa0791a155a49c724","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/eacq-payform-core/v/20.3.6"}],"affected":[{"package":{"name":"eacq-payform-core","ecosystem":"npm","purl":"pkg:npm/eacq-payform-core"},"versions":["20.3.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_vendor.js","sha256":"4be2c3767068e0f7eb80aa4457882ad2c1f2267c4dae493c91aa1b0e49b6659a","tlsh":"e5b175aa166630188bb0dbe8c6175415f65bf26373508294f79c65985ff312483b2efc"}],"package_integrity":[{"filename":"eacq-payform-core-20.3.6.tgz","hashes":{"sha1":"c6e73e1993e084f5209706cba358d482a812cc7e","sha512_sri":"sha512-d3IeZd+bGdllFJu/TbrNwk52Ptvpa+/ysV1KGxmydHJjRmGHS/UxP7rM9dDJiM17nDxemtnH4+GC4d5g63GlJA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/eacq-payform-core/MAL-2026-11538.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}