{"id":"MAL-2026-12129","summary":"Malicious code in accounts-appointment (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b85924ae1e24ede2acf333de8af5ca1d8ae2854652be2b3b82a01df710adc27a)\nindex.js unconditionally requires./setup, which on load selects a platform-specific payload path, fetches bytes over HTTPS from Cloudflare workers.dev subdomains (oob-worker.cf99-9b3.workers.dev and siblings cf100-416/cf101-adf/cf103-070.workers.dev) with a DNS TXT-record fallback channel under *.dl.well1.site, writes the payload to /var/tmp or %TEMP% under decoy names resembling.NET diagnostic files (.cache_\u003chex\u003e / dotnet_diag_\u003chex\u003e.exe), chmods 0755 on unix, and spawns the file detached via /bin/sh -c or cmd.exe /c start. Endpoint hostnames are assembled via array-join string concatenation to evade static string search, and a secondary DNS TXT loader queries c.\u003cdomain\u003e for a chunk count and reassembles base64 chunks from N.\u003cdomain\u003e TXT records. The dropper fires on any require/import of the package and executes attacker-controlled code on the installer's host.\n","modified":"2026-08-05T10:05:42.476541462Z","published":"2026-08-05T09:07:08Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T09:07:08Z","sha256":"12cacc35ffc7d789f337229c235e234a9f6ac6f18d6ed1f30fa4024c0ea15d22","source":"amazon-inspector","versions":["33.2.6"],"id":"IN-MAL-2026-014552","import_time":"2026-08-05T09:28:24.825523273Z"},{"modified_time":"2026-08-05T09:07:48Z","sha256":"b85924ae1e24ede2acf333de8af5ca1d8ae2854652be2b3b82a01df710adc27a","source":"amazon-inspector","versions":["0.0.2"],"id":"IN-MAL-2026-014557","import_time":"2026-08-05T09:28:25.332784567Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/accounts-appointment/v/33.2.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/accounts-appointment/v/0.0.2"}],"affected":[{"package":{"name":"accounts-appointment","ecosystem":"npm","purl":"pkg:npm/accounts-appointment"},"versions":["33.2.6","0.0.2"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"6cb185aa156630294bb0e7e4c6175415f65bf663738082d0f79ca9985ff312482b2efc","path":"setup.js","sha256":"ea27e3070af8b91762daae369e2f85855c9392e07394a4f78b8fe62f668f6fbb"}],"package_integrity":[{"filename":"accounts-appointment-33.2.6.tgz","hashes":{"sha1":"be80b5d9a0a0c5098124e1f1a7f41f50a7e88133","sha512_sri":"sha512-GYl5YBxZTex7cws5WGqj8sjJlU/IbWXu7MaBi2YY4K/5YYAfUUxZYuuBVW0zQ+8/xwg3EhB+ROIarB1BfRDg8Q=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/accounts-appointment/MAL-2026-12129.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}