{"id":"MAL-2026-12643","summary":"Malicious code in claims-should-retry (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dfeb9953f0f268a6f342f7c5b8d31292bf0f0855b736149d56df7eab1e119ebd)\nOn require of the package, index.js loads _platform.js, which reconstructs destination hosts from split string arrays (e.g. Cloudflare Workers subdomains under oob-worker.cf*-*.workers.dev) via.join(\"\") to hide them from static inspection, downloads a platform-specific binary, writes it to /tmp or %TEMP% under a misleading name (dotnet_diag_*.exe or.cache_*), chmods it 0755, and spawns it detached with stdio ignored via child_process spawn against /bin/sh or cmd. If HTTP fetch fails, a DNS-TXT covert-channel fallback enumerates numbered TXT records under reconstructed *.dl.wel1.ru subdomains, base64-decodes and concatenates them into an executable buffer that is written and executed the same way. A.analytics_state / analytics_state marker file suppresses re-execution, opt-out environment variables (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) provide a telemetry cover story, and a no-op logger overwrites console output to suppress traces. The package is advertised as a claims-retry library and has no relation to fetching or executing platform binaries.\n","modified":"2026-08-05T14:36:04.566155622Z","published":"2026-08-05T14:02:50Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:20:06.382909289Z","modified_time":"2026-08-05T14:02:50Z","sha256":"dfeb9953f0f268a6f342f7c5b8d31292bf0f0855b736149d56df7eab1e119ebd","source":"amazon-inspector","versions":["35.6.8"],"id":"IN-MAL-2026-015142"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claims-should-retry/v/35.6.8"}],"affected":[{"package":{"name":"claims-should-retry","ecosystem":"npm","purl":"pkg:npm/claims-should-retry"},"versions":["35.6.8"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"a187cd2a583e0835e6dfb2c85caa99f7ef2b8380b75ee41fcca6952281b06db4","tlsh":"4ca1989a05a670194bb09be48b275416f56bf6633380c2d4fb5cb5881f7712483b2efc","path":"_platform.js"}],"package_integrity":[{"hashes":{"sha1":"49468fe661045c1d7f5c169688035dcb84d05ea8","sha512_sri":"sha512-3+oIKJ6J74inigFIE5W1Yms71nBQQ2T9iizZML4rfULSc80446HOvaUqCApPsBc/oXmyuh/TsaYLQ11DUwSNiw=="},"filename":"claims-should-retry-35.6.8.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-should-retry/MAL-2026-12643.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}