{"id":"MAL-2026-12179","summary":"Malicious code in fb-insurance--boxified-form-vzr-test (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a1527da37d48efd3c216bf62d4f3d167181948006ad5d8e88f2ff9fa40eb0875)\nOn require of the package, index.js loads _loader.js which selects a platform-specific endpoint, fetches an executable payload over HTTPS from hardcoded Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, cf100-416.workers.dev, cf103-070.workers.dev), writes it to /var/tmp or %TEMP% under a deceptive filename (`.cache_\u003chex\u003e` on POSIX, `dotnet_diag_\u003chex\u003e.exe` on Windows), chmods it 0755, and spawns it detached-and-unref'd via `/bin/sh -c` or `cmd`. If the HTTPS mirrors fail, _loader.js falls back to a DNS-TXT covert channel: it resolves `c.\u003cdomain\u003e` for a chunk count against resolvers under *.dl.well1.site (tin/tina/ldr/win subdomains) and reassembles N base64 TXT fragments from `\u003ci\u003e.\u003cdomain\u003e` into the same executable buffer. Destination hostnames and resolver domains are constructed at runtime by joining short substring arrays (e.g. ['oob-worker.cf99-9b3','.worker','s.dev'].join('')) to evade static string matching. No hash or signature is verified on the fetched bytes. The fetched executable runs with the installer's privileges.\n","modified":"2026-08-05T10:06:09.405858721Z","published":"2026-08-05T09:04:59Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T09:28:23.401704447Z","modified_time":"2026-08-05T09:04:59Z","sha256":"a1527da37d48efd3c216bf62d4f3d167181948006ad5d8e88f2ff9fa40eb0875","source":"amazon-inspector","versions":["20.3.7"],"id":"IN-MAL-2026-014537"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fb-insurance--boxified-form-vzr-test/v/20.3.7"}],"affected":[{"package":{"name":"fb-insurance--boxified-form-vzr-test","ecosystem":"npm","purl":"pkg:npm/fb-insurance--boxified-form-vzr-test"},"versions":["20.3.7"],"database_specific":{"indicators":{"package_integrity":[{"filename":"fb-insurance--boxified-form-vzr-test-20.3.7.tgz","hashes":{"sha1":"eced97bb7053e6e974af17d7639ab1e16dad91a8","sha512_sri":"sha512-UO6erBA0tb6wnk8JoR7+VVUJ7/thSdJpSxZpRM/4FKxj5ShZECIpOpmjUQZMw1KIwwisDwiFwpC1Sav/EqFvqQ=="}}],"evidence_files":[{"path":"_loader.js","sha256":"8f4b71e41252439a015622455feddca488cff6f49108206b3d0fd58847ac8e3a","tlsh":"dfa1b49a16a5701d8bb0e7e1c71b4816f61bf2633390d294fb9c69945fb24248372efc"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fb-insurance--boxified-form-vzr-test/MAL-2026-12179.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}