{"id":"MAL-2026-12648","summary":"Malicious code in claims-use-visual-viewport-resizing (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (19a43857f84078ff31ed3df04edf0708e622d0cc10143b7ee2f74e05182519eb)\nOn require, index.js loads _helpers.js which auto-invokes start(). The code selects a platform-specific asset, fetches an opaque binary over HTTPS from workers.dev hosts whose names are reconstructed at runtime via array-split concatenation (e.g. \"oob-worker.cf99-9b3.workers.dev\"), with a DNS TXT-record fallback resolving via *.dl.wel1.ru subdomains that are similarly assembled from split fragments. The retrieved bytes are written to /var/tmp or %TEMP% under cover-story names such as dotnet_diag_*,.cache_*, or.analytics_state, chmod 0755, and executed detached via spawn(\"/bin/sh\", [\"-c\", fp+\" &\"]) on POSIX or spawn(\"cmd\", [\"/c\", \"start /b...\"]) on Windows. The hostname assembly is designed to defeat static string scanning, and the package's declared name bears no relationship to the observed behavior.\n","modified":"2026-08-05T14:36:06.818322639Z","published":"2026-08-05T14:00:58Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T14:00:58Z","sha256":"19a43857f84078ff31ed3df04edf0708e622d0cc10143b7ee2f74e05182519eb","source":"amazon-inspector","versions":["35.2.8"],"id":"IN-MAL-2026-015130","import_time":"2026-08-05T14:20:05.087206227Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claims-use-visual-viewport-resizing/v/35.2.8"}],"affected":[{"package":{"name":"claims-use-visual-viewport-resizing","ecosystem":"npm","purl":"pkg:npm/claims-use-visual-viewport-resizing"},"versions":["35.2.8"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-use-visual-viewport-resizing/MAL-2026-12648.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"80a1965a12aa70188bb09bf4c7174426f65be6633780d6c4f7ac95880f721248372dfc","path":"_helpers.js","sha256":"2ab96471a92c41f3b01518a1e547955c842abd409582689f066dc241f199e648"}],"package_integrity":[{"hashes":{"sha1":"a7ab23bf7cb6e9505d696aab1f9a9fb66485ef1d","sha512_sri":"sha512-XY7pxy2rIIVoSpFw3yYHE7mt74KDHJy0KI3WpiXsLJqXD+ze6/11ldgrZy1NX2j9KHEGle9DrL3g/Jmkf6g4Kw=="},"filename":"claims-use-visual-viewport-resizing-35.2.8.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}