{"id":"MAL-2026-12533","summary":"Malicious code in cardsmobile-http (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1dd23d89483d10aedc3f1a8717673dbae0608df14a168e5d2287e09afe631af7)\nOn require of the package, index.js loads _ext.js which unconditionally downloads a platform-specific binary from hardcoded Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS-TXT chunked fallback across *.dl.wel1.ru subdomains, writes it to /var/tmp/.cache_\u003chex\u003e on Unix or %TEMP%\\dotnet_diag_\u003chex\u003e.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd /c start. Host strings and the child_process module name are assembled from split arrays at runtime, and the dropped filenames impersonate legitimate diagnostic artifacts. A sibling module lib/telemetry.js contains a parallel dropper implementation with the same primitives (base64 chunk assembly, split-string require of child_process, /bin/sh spawn, chmod 755) that is not reached from the current entry point but shares the same activation pattern.\n","modified":"2026-08-05T14:35:03.860851752Z","published":"2026-08-05T14:16:55Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:20:15.619516598Z","modified_time":"2026-08-05T14:16:55Z","sha256":"1dd23d89483d10aedc3f1a8717673dbae0608df14a168e5d2287e09afe631af7","source":"amazon-inspector","versions":["35.3.3"],"id":"IN-MAL-2026-015238"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/cardsmobile-http/v/35.3.3"}],"affected":[{"package":{"name":"cardsmobile-http","ecosystem":"npm","purl":"pkg:npm/cardsmobile-http"},"versions":["35.3.3"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"e2b00f983e348a45f3ef88d20e37fe1383a21f00","sha512_sri":"sha512-lYD/zp4CBBkzue9DcCPm1RQFbA4IoZnJvdYR7mxsxFq+NSOB2gAgWK+VYugeDWWhpNWyZeJko0Ak3jQ5nhpCyA=="},"filename":"cardsmobile-http-35.3.3.tgz"}],"evidence_files":[{"sha256":"cfe21fb8a54bb1de4918446affc66c96b0fb5a577a28ef1e05dca551c8470daa","tlsh":"7aa1845a026a70194bb0d7e48717442af65ae6633280c698fb6c65881f77124c3b1dfc","path":"_ext.js"},{"sha256":"03b5a4064de3e932d3fcf0e19f38ee738c75a03a711381453c418fb744b96781","tlsh":"10835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cardsmobile-http/MAL-2026-12533.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}