{"id":"MAL-2026-12620","summary":"Malicious code in claims-get-error-string (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8107a092447bc749767928c38a816191c2af0ea06cb12d6dbeddb9f09b46c698)\nOn require(), index.js loads _ext.js which downloads a platform-specific binary from a set of hardcoded Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev) assembled by string-splitting to evade static matching. The downloaded bytes are written to /var/tmp or %TEMP% under innocuous names (.cache_\u003crnd\u003e on POSIX, dotnet_diag_\u003crnd\u003e.exe on Windows), chmod 0755 is applied, and the binary is spawned detached via /bin/sh -c '\u003cpath\u003e &' or cmd. A DNS-TXT covert channel under wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru) reads a chunk count from c.\u003cdomain\u003e and base64-reassembles the payload from sequential subdomain TXT records as a delivery fallback. A second module lib/telemetry.js (81KB) is bundled in the tarball with parallel dropper logic (base64 chunk assembly, chmod 0755, cp.spawn('/bin/sh', ['-c', filePath+' &'])) though not reachable from main in this version. No hash pinning, no signature verification, opaque payload, cover-story naming as analytics/telemetry.\n","modified":"2026-08-05T14:35:52.852360652Z","published":"2026-08-05T14:04:32Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015153","import_time":"2026-08-05T14:20:07.565094538Z","modified_time":"2026-08-05T14:04:32Z","sha256":"8107a092447bc749767928c38a816191c2af0ea06cb12d6dbeddb9f09b46c698","source":"amazon-inspector","versions":["35.5.9"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claims-get-error-string/v/35.5.9"}],"affected":[{"package":{"name":"claims-get-error-string","ecosystem":"npm","purl":"pkg:npm/claims-get-error-string"},"versions":["35.5.9"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"a242f14ade81a3463385ec3fc3c47d8f8acb85ac2b75306cf9ba2e379c7bc003","tlsh":"8ea1979a06a670098bb0d7e48a275406f65bf5633780c294fb5ca9985f7712483b2efc","path":"_ext.js"},{"tlsh":"89835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js","sha256":"1fc89cc0e59bc4da9625b1d5d43b750eb69a5bd1c0d8cd29f670f0bcde1743e7"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-Q2XH0kDxbqxwQCPWJfKavevBivMJRSktxcmS7CIza7tbf72dEK7nmmLQkN0OMNavhwVLCMaRexBinGJzRSEKQw==","sha1":"452ee8d37f96b40ab9880d7d47acf21e654de34f"},"filename":"claims-get-error-string-35.5.9.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-get-error-string/MAL-2026-12620.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}