{"id":"MAL-2026-12178","summary":"Malicious code in fb-cards-form-no-resident-information (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0f5f533e1e08aafbda3bd64998ad984e90345592ecc1a9fd14f6d449413e6c87)\nOn require() of the package, index.js loads _adapter.js which reconstructs Cloudflare Workers hostnames from split string fragments (e.g. 'oob-worker' + '.cf101-a' + 'df.workers.dev') and downloads a platform-specific binary via https.get. A DNS TXT resolver fallback against subdomains of dl.well1.site retrieves a base64-chunked payload across numbered subdomains as an out-of-band channel. The fetched bytes are written to /tmp or %TEMP% under disguised names (.cache_\u003crnd\u003e, dotnet_diag_\u003crnd\u003e.exe), chmod 0755, and spawned detached via spawn('/bin/sh', ['-c', fp+' &'], {detached:true}) or spawn('cmd',...). No hash or signature verification is performed; the destinations are unrelated to the package's stated purpose and are not publisher-owned infrastructure. An opt-out environment variable check is present as a cover story.\n","modified":"2026-08-05T10:06:08.717558713Z","published":"2026-08-05T09:09:00Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014566","import_time":"2026-08-05T09:28:26.204735404Z","modified_time":"2026-08-05T09:09:00Z","sha256":"0f5f533e1e08aafbda3bd64998ad984e90345592ecc1a9fd14f6d449413e6c87","source":"amazon-inspector","versions":["20.4.4"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fb-cards-form-no-resident-information/v/20.4.4"}],"affected":[{"package":{"name":"fb-cards-form-no-resident-information","ecosystem":"npm","purl":"pkg:npm/fb-cards-form-no-resident-information"},"versions":["20.4.4"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"_adapter.js","sha256":"cc1ab7e681bf91678197420594306901ee5993b3c195000efce70db9d2a9b486","tlsh":"8fb1856a15a570184bb0dbe1cb17541af65af663738081d4fb9ca49c5fb2224c2f2efc"}],"package_integrity":[{"hashes":{"sha1":"e18d0243cb86fa3ed97fc139cce1c4bf526bcb6a","sha512_sri":"sha512-L94bErSy9uChCZnHXkslINUKbvHjwphleIWZqr9vksy0erDRD0O0qlk7bhLZFegBIrAL6DQq6LYTDtSEFl5REA=="},"filename":"fb-cards-form-no-resident-information-20.4.4.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fb-cards-form-no-resident-information/MAL-2026-12178.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}