{"id":"MAL-2026-12644","summary":"Malicious code in claims-to-iso-string-with-timezone (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c313bb681d365fedf6993c01c72c1e6e703b2b5124c8c35c19a730d5b2d4f7aa)\nOn require of claims-to-iso-string-with-timezone, index.js loads./_init.js which downloads a platform-specific binary from obfuscated author-controlled endpoints (Cloudflare Workers hostnames oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev with a DNS-TXT fallback to sdk.dl.wel1.ru) reconstructed from string-array joins, writes it to /tmp/.cache_\u003crand\u003e or %TEMP%\\dotnet_diag_\u003crnd\u003e.exe, chmods it 0755, and spawns it detached via cp.spawn(\"/bin/sh\", [\"-c\", fp + \" &\"]) or spawn(\"cmd\",...). The package advertises itself as a date/timezone formatting utility with no declared dependencies; the dropper require is wrapped in a try/catch to swallow errors, and the dropped binary is named to impersonate dotnet diagnostic tooling. The package name resembles a legitimate date-formatting utility, and the harmful behavior is isolated in _init.js loaded by index.js.\n","modified":"2026-08-05T14:36:05.419698072Z","published":"2026-08-05T14:01:45Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:20:05.573973414Z","modified_time":"2026-08-05T14:01:45Z","sha256":"c313bb681d365fedf6993c01c72c1e6e703b2b5124c8c35c19a730d5b2d4f7aa","source":"amazon-inspector","versions":["35.7.2"],"id":"IN-MAL-2026-015135"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claims-to-iso-string-with-timezone/v/35.7.2"}],"affected":[{"package":{"name":"claims-to-iso-string-with-timezone","ecosystem":"npm","purl":"pkg:npm/claims-to-iso-string-with-timezone"},"versions":["35.7.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"f3a1965a16a6300c87b09bf487175415f55be66333c08288fb9c79981fb216483b2efc","path":"_init.js","sha256":"5b7d25551f8a7a0f60b5f69c90ed13edca64490ed8474d6a097a3b062124baf6"},{"path":"package.json","sha256":"15e66e39164c4ea9b50d54cbe48c5a82625d73ccac85569acfae29c7f3d18e42","tlsh":"02d0a773453156770dfe42905ce2861b3b650f3f5175bd1ab6fb150814e527600ad331"}],"package_integrity":[{"filename":"claims-to-iso-string-with-timezone-35.7.2.tgz","hashes":{"sha512_sri":"sha512-/L0jDrofJunuUkl4mZ9qgjcVTSMVjf+1J/HCxuG6GmQukGUWEPrZOohmArYdFIc17gAXROUUiIn/nEkmd3UDPQ==","sha1":"562a115a5e83339f54527e8cec5e4b9f9cfd2ede"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-to-iso-string-with-timezone/MAL-2026-12644.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}