{"id":"MAL-2026-12638","summary":"Malicious code in claims-policies-domain (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5858353e2874492da6b051be8fa2e6061317bc0ac825838f13c6a1b2471c90b5)\nclaims-policies-domain@35.3.3 executes a binary dropper on module load. index.js requires./_platform, which selects a platform-specific path, fetches a binary from one of three hardcoded Cloudflare Workers endpoints (oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS TXT fallback channel under *.dl.wel1.ru, writes the bytes to /var/tmp/.cache_\u003chex\u003e on Unix or %TEMP%\\dotnet_diag_\u003chex\u003e.exe on Windows, chmods the file to 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. No hash or signature verification is performed. Destination hostnames and sensitive API names (child_process, chmodSync, hostname) are assembled at runtime from split string fragments to defeat static analysis (e.g. [\"oob-worker.cf102-baf.wo\",\"rkers.\",\"dev\"].join(\"\"), require(\"child_\" + \"process\")). The dropped filename mimics a.NET diagnostic tool on Windows and a hidden dotfile on Unix, and a cooldown marker is written as.analytics_state. The package's advertised purpose as a lightweight claims-policies wrapper does not require fetching or executing a native binary from anonymous worker hosts.\n","modified":"2026-08-05T14:36:01.724964722Z","published":"2026-08-05T14:00:51Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.3.3"],"id":"IN-MAL-2026-015129","import_time":"2026-08-05T14:20:05.007814399Z","modified_time":"2026-08-05T14:00:51Z","sha256":"5858353e2874492da6b051be8fa2e6061317bc0ac825838f13c6a1b2471c90b5"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claims-policies-domain/v/35.3.3"}],"affected":[{"package":{"name":"claims-policies-domain","ecosystem":"npm","purl":"pkg:npm/claims-policies-domain"},"versions":["35.3.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"claims-policies-domain-35.3.3.tgz","hashes":{"sha512_sri":"sha512-J9BIntvZArruRTBCIKOjT21ypPw+VYCyK6fvyqzyAwsCvoGajyqXNutWTwD/b9GCzmwt4yRlO+2BXfUpldsAyQ==","sha1":"6c5e1556bee0937b9563db36f0df35e80f694f1d"}}],"evidence_files":[{"path":"_platform.js","sha256":"e9e85fd503f53f32394b9c38e27c8e1c74e2d72844e0f604dbee35f87486c667","tlsh":"66a1979a16a670184b709be4c6275416f65be2633380c2d4fb5ca9981fb35348372efc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-policies-domain/MAL-2026-12638.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}