{"id":"MAL-2026-12657","summary":"Malicious code in cobrowsing-redis-module (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (502c907b28a2866d4fc67be93a6417e535336938ce3e8c23f0f95e927c6711b6)\nindex.js unconditionally requires./_loader on import. _loader.js selects a platform-specific endpoint, assembles C2 hostnames at runtime from split string arrays (e.g. [\"oob-worker.cf99-9b3.workers\",\".d\",\"ev\"].join(\"\")) pointing at oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, and oob-worker.cf100-416.workers.dev, downloads bytes via https.get, writes them to /var/tmp or %TEMP% under disguised names (dotnet_diag_\u003chex\u003e.exe on Windows,.cache_\u003chex\u003e on POSIX), chmods 0755, and spawns the file detached via /bin/sh -c or cmd.exe. When HTTPS fails, a DNS-TXT covert channel over sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru reassembles the payload from base64 TXT chunks (c.\u003cdomain\u003e for chunk count, \u003ci\u003e.\u003cdomain\u003e for each chunk) via Buffer.from(...,'base64'). No hash or signature verification is performed. A.analytics_state stamp file and DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK env-var gates are used as cover-story framing; the destinations and behavior are unrelated to any Redis or cobrowsing functionality. The package name and README present it as an internal Redis wrapper while the sibling _loader.js contains only the dropper.\n","modified":"2026-08-05T14:36:11.025913190Z","published":"2026-08-05T13:57:25Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T13:57:25Z","sha256":"502c907b28a2866d4fc67be93a6417e535336938ce3e8c23f0f95e927c6711b6","source":"amazon-inspector","versions":["35.4.7"],"id":"IN-MAL-2026-015107","import_time":"2026-08-05T14:20:02.747749987Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/cobrowsing-redis-module/v/35.4.7"}],"affected":[{"package":{"name":"cobrowsing-redis-module","ecosystem":"npm","purl":"pkg:npm/cobrowsing-redis-module"},"versions":["35.4.7"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"4b7de7781d520e482340fd228ca9334eb8e8037bc67df6feaebc8395837d4dff","tlsh":"c3a1646a166a71084bb0ebf4ca274416f55bf6633780c684f79c69885f7252482b2efc","path":"_loader.js"}],"package_integrity":[{"filename":"cobrowsing-redis-module-35.4.7.tgz","hashes":{"sha512_sri":"sha512-K4pkH/3b1k+9Uk03Bj5IIn68xqiQDx7O8nfzXWapsI3Fcg98evM07B99UaVMeQ3060b5rCGUF4jI90Jdg/LkFQ==","sha1":"9712d4cb1b575991a6dc2c4c3bbb3fbee9efa63b"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cobrowsing-redis-module/MAL-2026-12657.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}