{"id":"MAL-2026-12609","summary":"Malicious code in claims-block-visibility (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b6afd966a220b14c0d01a2132af36d206eee200ab806d61443b66379e560b324)\nOn require('claims-block-visibility'), index.js loads _polyfill.js which unconditionally runs a setup routine that selects an OS-specific endpoint, downloads a binary from one of several string-concatenation-obfuscated hosts under *.workers.dev, and falls back to a chunked base64-over-DNS-TXT channel under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru when HTTPS is unavailable. The fetched bytes are written to a temp path disguised as.cache_\u003chex\u003e or dotnet_diag_\u003chex\u003e.exe, chmod 0755, and spawned detached via /bin/sh -c or cmd.exe with unref(). Destination hostnames are assembled from split string arrays (e.g. ['oob','-worker','.cf103-',...].join('')) and require('child_process') is masked as require('child_'+'process'). A cache-stamp file is written under a benign '.analytics_state' name. The behavior fires on module load, giving any consumer that requires this package a fetch-and-execute of opaque attacker-controlled native code.\n","modified":"2026-08-05T14:35:48.139613750Z","published":"2026-08-05T14:06:50Z","database_specific":{"malicious-packages-origins":[{"sha256":"b6afd966a220b14c0d01a2132af36d206eee200ab806d61443b66379e560b324","source":"amazon-inspector","versions":["35.3.8"],"id":"IN-MAL-2026-015169","import_time":"2026-08-05T14:20:09.048504383Z","modified_time":"2026-08-05T14:06:50Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claims-block-visibility/v/35.3.8"}],"affected":[{"package":{"name":"claims-block-visibility","ecosystem":"npm","purl":"pkg:npm/claims-block-visibility"},"versions":["35.3.8"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-block-visibility/MAL-2026-12609.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_polyfill.js","sha256":"17068c4eb118c7c97fb6732e645ca12b2b0eacb7c7176253cb82ecfb68683108","tlsh":"6fa1736a026670084bb0dbe9ca175416f65af6633780c6d4f7ac65885fb212483f2efc"}],"package_integrity":[{"filename":"claims-block-visibility-35.3.8.tgz","hashes":{"sha1":"55b591094847600e6c2489271000b419122a1771","sha512_sri":"sha512-P04mWpdrvilGdmFwwRs4IFWdvzQgxqDyVJNfEpYbt+g+hZL5pX5xqHZcPP91KzS7cR0ouTjy/ajqQAkOCzgkDA=="}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}