{"id":"MAL-2026-12619","summary":"Malicious code in claims-get-base-url (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7e7b7dbbb58284ead0ecb4d93490e9683b4f58b31955d817de52495fb7399106)\nindex.js requires./setup on load, so any require() of this package triggers a dropper chain. setup.js selects a platform-specific payload path (linux/darwin/win32), downloads a binary over HTTPS from string-split-obfuscated hosts of the form oob-worker.cf10X-*.workers.dev with a DNS TXT-record fallback channel under sdk.dl.wel1.ru (hostnames are assembled at runtime via array joins such as [\"oob-worker.cf102-baf.workers.de\",\"v\"].join(\"\") to hide the.dev TLD from static scanners), writes it to a hidden path under /var/tmp or %TEMP% (.cache_\u003chex\u003e / dotnet_diag_\u003chex\u003e.exe), chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe with stdio ignored and unref()'d. lib/telemetry.js contains a second, dormant copy of the same dropper shape (base64 chunk assembly, chmod 0755, detached /bin/sh spawn), referencing child_process as 'child_'+'process'. The package's advertised purpose (\"claims get base url interface\") has no legitimate need for cross-platform binary fetch-and-execute; the obfuscation, DNS fallback channel, and hidden dotfile staging are canonical import-time dropper tradecraft. Installing and loading this package runs attacker-controlled native code on the installer's machine.\n","modified":"2026-08-05T14:35:52.362684177Z","published":"2026-08-05T14:05:09Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:20:07.900023887Z","modified_time":"2026-08-05T14:05:09Z","sha256":"7e7b7dbbb58284ead0ecb4d93490e9683b4f58b31955d817de52495fb7399106","source":"amazon-inspector","versions":["35.4.5"],"id":"IN-MAL-2026-015157"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claims-get-base-url/v/35.4.5"}],"affected":[{"package":{"name":"claims-get-base-url","ecosystem":"npm","purl":"pkg:npm/claims-get-base-url"},"versions":["35.4.5"],"database_specific":{"indicators":{"package_integrity":[{"filename":"claims-get-base-url-35.4.5.tgz","hashes":{"sha1":"5e85e6da95a66afc4b230ca34f1532c54a2e46da","sha512_sri":"sha512-nE+qkub7I2CtpKgdyRxFlNN2tUDsYtisH6/deN6NOSaIt35jx2KCcLj00cNsQFOZ0WaxjYOOHFuW5ScDi9norA=="}}],"evidence_files":[{"path":"setup.js","sha256":"384db83dcadb00c4c56739ce740aa8e093ef2a6519205c3ec6ededba89dba57e","tlsh":"14b1965a16aa70198bf0d7e0cb175815f65af6633380c2d4fb5ca4884f7612883b2dfc"},{"tlsh":"99835055566a242186b2b378df234107ff3685272643429dbaec82dc1fbd72092a5ffc","path":"lib/telemetry.js","sha256":"f267201ef479a29acd2e40a222c6f1fd709fa19a04696bb70c96bafc36d2b31b"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-get-base-url/MAL-2026-12619.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}