{"id":"MAL-2026-12673","summary":"Malicious code in ded-ps-ded-ps-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cfe3941502d9792a1ad46ba7ed447227ef74d1c45cce8e9996005218d47f0f51)\nOn require(), index.js loads _init.js, which selects a platform-specific endpoint and fetches an opaque native binary from Cloudflare Workers hosts whose names are assembled at runtime by joining split string fragments (e.g. oob-worker.cf1-01-adf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS TXT covert-channel fallback to base64-chunked subdomains of wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru). The fetched binary is written to /tmp/.cache_\u003chex\u003e on Unix or %TEMP%/dotnet_diag_\u003chex\u003e.exe on Windows — filenames chosen to mimic hidden cache and.NET diagnostics artifacts — then chmod 0755 and spawned detached via /bin/sh -c or cmd.exe start /b. lib/telemetry.js additionally constructs sensitive API names at runtime (require(\"child_\" + \"process\"), fs[\"chmod\" + \"Sync\"]) to evade static analysis. Requiring the package causes arbitrary attacker-controlled native code to execute on the installer's host.\n","modified":"2026-08-05T14:36:19.953153722Z","published":"2026-08-05T13:56:45Z","database_specific":{"malicious-packages-origins":[{"sha256":"cfe3941502d9792a1ad46ba7ed447227ef74d1c45cce8e9996005218d47f0f51","source":"amazon-inspector","versions":["35.9.1"],"id":"IN-MAL-2026-015103","import_time":"2026-08-05T14:20:02.300494928Z","modified_time":"2026-08-05T13:56:45Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ded-ps-ded-ps-core/v/35.9.1"}],"affected":[{"package":{"name":"ded-ps-ded-ps-core","ecosystem":"npm","purl":"pkg:npm/ded-ps-ded-ps-core"},"versions":["35.9.1"],"database_specific":{"indicators":{"evidence_files":[{"path":"_init.js","sha256":"dd4428a60cc0d8951bfd661f5bdebabf6653cf3eb4fb3c5f881d7d2de460665e","tlsh":"96a1c7aa11a670194b70dbe0cb175416f55bf6637380c284f79ca9981ff251483b2efc"}],"package_integrity":[{"filename":"ded-ps-ded-ps-core-35.9.1.tgz","hashes":{"sha512_sri":"sha512-Z4QzNzaF0orQVig9tiBMpxyUGIVKT8gjN8rhE2q0NsNGDmqZm/q0oLWFDjGDPJhrUE1lQsdlKdCSMjSjcNQUeQ==","sha1":"ff4c6f187cd980b6451b33b183c20b102f55eb4d"}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ded-ps-ded-ps-core/MAL-2026-12673.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}