{"id":"MAL-2026-12537","summary":"Malicious code in cbp-exchange-government-cbp-exchange-government-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4e8845f778d906df5e69c06c91840deb7718a94ccacdd371c987b003f6d85bdb)\nindex.js unconditionally requires./_loader on module load. _loader.js assembles three Cloudflare Workers hostnames via split-array `.join(\"\")` obfuscation (oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev), fetches an opaque platform-specific native binary via `https.get`, writes it to /var/tmp or %TEMP% under a decoy name (e.g. dotnet_diag_\u003chex\u003e.exe,.cache_\u003chex\u003e), chmods it 0755, and spawns it detached via `cp.spawn(\"/bin/sh\", [\"-c\", fp + \" &\"], {detached:true}).unref()` (or `spawn(\"cmd\",...)` on Windows). A secondary DNS-TXT covert channel under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru reconstructs a base64-encoded payload from numbered TXT records (`c.\u003cdomain\u003e` count + `\u003ci\u003e.\u003cdomain\u003e` chunks) when the HTTPS fetch fails. The binary is unpinned, unhashed, and served from anonymous Workers subdomains — arbitrary attacker-controlled code executes on any host that installs or requires the package. lib/telemetry.js contains parallel dropper primitives (split-string `require(\"child_\" + \"process\")`, `fs[\"chmod\" + \"Sync\"]`, `cp.spawn(\"/bin/sh\",...)`) staged but not currently reachable from the main entry.\n","modified":"2026-08-05T14:35:06.160343953Z","published":"2026-08-05T14:16:45Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T14:16:45Z","sha256":"4e8845f778d906df5e69c06c91840deb7718a94ccacdd371c987b003f6d85bdb","source":"amazon-inspector","versions":["35.3.3"],"id":"IN-MAL-2026-015237","import_time":"2026-08-05T14:20:15.538662226Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/cbp-exchange-government-cbp-exchange-government-core/v/35.3.3"}],"affected":[{"package":{"name":"cbp-exchange-government-cbp-exchange-government-core","ecosystem":"npm","purl":"pkg:npm/cbp-exchange-government-cbp-exchange-government-core"},"versions":["35.3.3"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"_loader.js","sha256":"7048b1c3f4b2dfd7a8ac69e1a00effd00735619b396ea9ccc1895587659929e6","tlsh":"f7a1975616a670184bb0a7e4c71b9425f55bf6633b81d2d4fbaca5841f7302483b2efc"},{"sha256":"8eea519a4e746d08577c51947477d28495dde807089c952564659928cd85df11","tlsh":"13835055566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}],"package_integrity":[{"filename":"cbp-exchange-government-cbp-exchange-government-core-35.3.3.tgz","hashes":{"sha512_sri":"sha512-ILPZkmAm/B+eI1DMLPIPNShN1JhHktTnsw8/RO33THnweOEfvnx1idqoA/95E+Kj40KSYEjr8K6tsX1kcmFPDQ==","sha1":"e42f8fea808d9871826743998eba68866089aaeb"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cbp-exchange-government-cbp-exchange-government-core/MAL-2026-12537.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}