{"id":"MAL-2026-12538","summary":"Malicious code in certificates-revocation-sw (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3037d3d739bf6d25fbb06a613915278de458d3b90547bdbf11b2710b7d88d82a)\nThe package's index.js unconditionally loads _bootstrap.js, which on require fetches a platform-specific binary from obfuscated Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev and similar, assembled by joining split string fragments) with a DNS-TXT chunked-base64 fallback via *.dl.wel1.ru, writes it to /tmp or %TEMP% under disguised names (.cache_\u003chex\u003e on POSIX, dotnet_diag_\u003chex\u003e.exe on Windows), chmods 0755, and spawns it detached via /bin/sh -c '\u003cpath\u003e &' or cmd.exe /c start /b. The package advertises itself as a certificate-revocation provider but contains no such functionality; the dropper is gated by cover-story env vars (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) and mislabeled with 'telemetry'/'analytics' comments. Hostname obfuscation, disguised drop paths, detached execution, and the mismatch between advertised purpose and actual behavior indicate a deliberate remote-code-execution dropper against the installer's host.\n","modified":"2026-08-05T14:35:07.075887281Z","published":"2026-08-05T14:17:30Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:20:15.953992679Z","modified_time":"2026-08-05T14:17:30Z","sha256":"3037d3d739bf6d25fbb06a613915278de458d3b90547bdbf11b2710b7d88d82a","source":"amazon-inspector","versions":["35.6.4"],"id":"IN-MAL-2026-015242"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/certificates-revocation-sw/v/35.6.4"}],"affected":[{"package":{"name":"certificates-revocation-sw","ecosystem":"npm","purl":"pkg:npm/certificates-revocation-sw"},"versions":["35.6.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/certificates-revocation-sw/MAL-2026-12538.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_bootstrap.js","sha256":"6f283b7bcd0d966ae929d9be0965a11b6981c1946e0bad76083c99730379928d","tlsh":"2db17496166970294bb0d7f4871b4416f65af6a33380c284fb5ca9981f73124c2b2efc"}],"package_integrity":[{"filename":"certificates-revocation-sw-35.6.4.tgz","hashes":{"sha1":"1f07aaa14732da8fcfe61ac1e6994b1faa174da8","sha512_sri":"sha512-JB+d2zlRa9nMe2fTQpPXfpHYUAjmBnZiWXUPWPJBaIuU3lfMsD4BabshAY3rWEVotSWjVM7dfCSAqzZxq7PQ/w=="}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}