{"id":"MAL-2026-12641","summary":"Malicious code in claims-replace-url-params (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cfdefc5cd3c5418949e2da9656f7b93b174c5b8eb5fa64531736fbd5ae63b1f0)\nThe package's public API in index.js is a no-op class whose only real effect is `require(\"./_adapter\")` on load. _adapter.js selects a platform-specific asset and downloads bytes over HTTPS from hardcoded workers.dev hosts (oob-worker.cf101-adf.workers.dev) with a DNS-TXT fallback that assembles base64 chunks from *.dl.wel1.ru subdomains (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru). The fetched bytes are written to /var/tmp/.cache_\u003chex\u003e on Unix or %TEMP%\\dotnet_diag_\u003chex\u003e.exe on Windows, chmodded 0755, and spawned detached via /bin/sh -c or cmd.exe /c start. Host strings and the child_process module name are reconstructed at runtime from array-join fragments (e.g. [\"oob-worker.cf\",\"101-adf\",\".worke\",\"rs.d\",\"ev\"].join(\"\"), require(\"child_\" + \"process\")) to defeat static string matching. lib/telemetry.js duplicates the same fetch-\u003ebase64-\u003ewrite-\u003echmod 0755-\u003espawn pipeline under an 'analytics SDK' label. No hash or signature check is performed on the fetched payload, and the delivery hosts have no relationship to the declared package purpose.\n","modified":"2026-08-05T14:36:03.251684787Z","published":"2026-08-05T14:01:15Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.3.2"],"id":"IN-MAL-2026-015132","import_time":"2026-08-05T14:20:05.313354066Z","modified_time":"2026-08-05T14:01:15Z","sha256":"cfdefc5cd3c5418949e2da9656f7b93b174c5b8eb5fa64531736fbd5ae63b1f0"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claims-replace-url-params/v/35.3.2"}],"affected":[{"package":{"name":"claims-replace-url-params","ecosystem":"npm","purl":"pkg:npm/claims-replace-url-params"},"versions":["35.3.2"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"claims-replace-url-params-35.3.2.tgz","hashes":{"sha1":"720812d281dc6e87f3d7d6d5e28e3af9fd4d2d2c","sha512_sri":"sha512-4YwT2kzttBPRK4uwZXQwF48WGr5oYRTMuUZMX/hQJjbB+eg9GEn9Tr261NKt7y1VF9DAV12YT0WqHrBHuRsk6Q=="}}],"evidence_files":[{"path":"_adapter.js","sha256":"b2bc48ab04450bafd36fc087b8eab9530660b65850c63a8d6406e3f372a45386","tlsh":"6fb1a796029670184bb0e7e4c6178825f65bf6633780d294fb5c69945fb3124c3b2efc"},{"tlsh":"ce835055566a242186b2b368df234107ff3685272642429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js","sha256":"039507df33fbd32e4a9564dec308d47df0147a996580d120c2b52d8ac31c7adf"},{"sha256":"894b6899c80aee2f751c027a0513b42b9c7c7a5137c0b878d87121e44345a13a","tlsh":"0cf0fc8611daf5e386b0e7e6ceb38071f67284215a4b515479c464df0fa8d1442d8e7a","path":"index.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-replace-url-params/MAL-2026-12641.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}