{"id":"MAL-2026-12634","summary":"Malicious code in claims-payout-offer-domain (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b7e5ae73b4b2f79e2790e4c9f503a3f469166c8d5587f7e84ac6a09022d1617f)\nOn require() of the package, index.js unconditionally loads _vendor.js, which selects an OS/arch-specific payload path and fetches an opaque binary over HTTPS from string-obfuscated Cloudflare Workers hosts (oob-worker.cf*-*.workers.dev, assembled at runtime via array-join to evade static analysis). A DNS-TXT covert-channel fallback reads a chunk count from c.dl.wel1.ru and reassembles base64-encoded bytes across numbered subdomains of dl.wel1.ru. The fetched bytes are written to /tmp or %TEMP% under disguised names (e.g. dotnet_diag_*.exe,.cache_*), chmod 0755, and spawned detached via /bin/sh -c or cmd. No pinning, hash check, or signature verification is performed, and the destinations are not the publisher's infrastructure.\n","modified":"2026-08-05T14:35:59.769114229Z","published":"2026-08-05T14:02:24Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:20:06.031794093Z","modified_time":"2026-08-05T14:02:24Z","sha256":"b7e5ae73b4b2f79e2790e4c9f503a3f469166c8d5587f7e84ac6a09022d1617f","source":"amazon-inspector","versions":["35.6.1"],"id":"IN-MAL-2026-015139"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claims-payout-offer-domain/v/35.6.1"}],"affected":[{"package":{"name":"claims-payout-offer-domain","ecosystem":"npm","purl":"pkg:npm/claims-payout-offer-domain"},"versions":["35.6.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_vendor.js","sha256":"82f6b2810b1acc6ad1b11d7126ca4306492fcb201e212c71640e1512bb2be42e","tlsh":"93a1a75a16a670184bb09be4c71b4416f65be66337c086c4f65ca9981f7613483b2efc"}],"package_integrity":[{"filename":"claims-payout-offer-domain-35.6.1.tgz","hashes":{"sha1":"04a8c1dc133fc54b4776e36511366cbf07c2c480","sha512_sri":"sha512-2bWyCBs3Qyqnve4SLlU15JVj0E0PHUdbYx8pNL86ktAgblmBmWJbWbWvFfRbpLDBOeR+9h8RlxMHlAzk7l1kYg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-payout-offer-domain/MAL-2026-12634.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}