{"id":"MAL-2026-12621","summary":"Malicious code in claims-get-indexed-selector (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fe924c35590524d1632020cce8e08d68b232aa0d53b0f0ecb730f3ae87e07c35)\nclaims-get-indexed-selector@35.8.7 executes a binary dropper on module load. index.js unconditionally requires _polyfill.js, which reassembles network destinations from split string arrays (hosts on cf*.workers.dev and *.dl.wel1.ru), downloads a native binary over HTTPS, writes it to /var/tmp/.cache_\u003chex\u003e or TEMP\\dotnet_diag_\u003chex\u003e.exe with cover-story filenames, chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. If HTTPS retrieval fails, a covert DNS-TXT channel is used: a chunk-count TXT record at c.\u003cdomain\u003e and base64-encoded payload chunks at \u003ci\u003e.\u003cdomain\u003e are fetched and reassembled into the executable. No hash or signature verification is performed on the fetched binary. Destination hostnames are constructed from split arrays such as [\"oob-worker\",\".cf103-070.\",\"workers.\",\"de\",\"v\"].join(\"\") to evade static string scanning. The package is presented as a benign runtime support module; the delivered binary is opaque and the destinations are attacker-controlled.\n","modified":"2026-08-05T14:35:53.333729776Z","published":"2026-08-05T14:06:00Z","database_specific":{"malicious-packages-origins":[{"versions":["35.8.7"],"id":"IN-MAL-2026-015163","import_time":"2026-08-05T14:20:08.457516187Z","modified_time":"2026-08-05T14:06:00Z","sha256":"fe924c35590524d1632020cce8e08d68b232aa0d53b0f0ecb730f3ae87e07c35","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claims-get-indexed-selector/v/35.8.7"}],"affected":[{"package":{"name":"claims-get-indexed-selector","ecosystem":"npm","purl":"pkg:npm/claims-get-indexed-selector"},"versions":["35.8.7"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"20b1a75a116670198bb0e7e4c717581af66af6637380c6d8fb5c55880f7712883b2efc","path":"_polyfill.js","sha256":"7c823ab3268fe994e0fdf7e7d0be9883b0bd75fce706abcaddd1e540ad730f1d"}],"package_integrity":[{"filename":"claims-get-indexed-selector-35.8.7.tgz","hashes":{"sha512_sri":"sha512-Ugwqk/DCrstfk9vKlzvFlH6E/8g2JEveNyNLOlBTbli2Yr3nfXSUy4I3knsL9nfGrW9u4Vg/maSO1r8k6HhnCA==","sha1":"4edcb830138a61fa4e318c8ac56cb1aa6308d0f9"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-get-indexed-selector/MAL-2026-12621.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}