{"id":"MAL-2026-12623","summary":"Malicious code in claims-handle-api-response (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0c11d3c5993128f5cb1eafd05487aeb9f630aee5bdef132bcf3d4b07bdfebe3e)\nThe package advertises itself as a REST client wrapper but its main entry (index.js) requires./setup on load. setup.js selects a platform-specific URL, downloads bytes over HTTPS from a rotating set of anonymous Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev), writes them to /tmp or %TEMP% under disguised names such as dotnet_diag_\u003chex\u003e.exe and.cache_\u003chex\u003e, chmods 0755, and spawns the file detached via /bin/sh -c or cmd. Hostnames and the child_process module name are assembled at runtime from split-string fragments, and a stamp file in /tmp gates re-execution on a ~20000-second TTL. If the HTTPS mirrors fail, setup.js falls back to a DNS-TXT covert channel: it resolves TXT records under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, reassembles chunked base64 into a binary, drops it, and executes it. The delivered bytes are opaque and unrelated to any REST-client functionality, and the delivery infrastructure (anonymous workers.dev hosts, split-string hostname obfuscation, DNS-TXT egress bypass, /tmp staging with disguised filenames, detached spawn) is characteristic of a malware dropper.\n","modified":"2026-08-05T14:35:54.325235377Z","published":"2026-08-05T14:04:07Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T14:04:07Z","sha256":"0c11d3c5993128f5cb1eafd05487aeb9f630aee5bdef132bcf3d4b07bdfebe3e","source":"amazon-inspector","versions":["35.4.9"],"id":"IN-MAL-2026-015150","import_time":"2026-08-05T14:20:07.283238769Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claims-handle-api-response/v/35.4.9"}],"affected":[{"package":{"name":"claims-handle-api-response","ecosystem":"npm","purl":"pkg:npm/claims-handle-api-response"},"versions":["35.4.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"claims-handle-api-response-35.4.9.tgz","hashes":{"sha1":"97ff41a89dde3e60903ad173745349cd9bb996f0","sha512_sri":"sha512-6hrsaCTyrEXFZ78Ht9vlFFoJaNMeefF7tuGM2yVQCbfGg8mOXxOWtFwJZwWTIod8YIB29H37NBco1tS0NBJfPw=="}}],"evidence_files":[{"tlsh":"5bb1535a16aa70084bb0d7e0c7174816f66af6a33781c684f79c69845f7312483b2efc","path":"setup.js","sha256":"67199b9108f6ff15d04407ce2e2dd5348bf9fd86ad2406269d438559be8ff40e"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-handle-api-response/MAL-2026-12623.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}