{"id":"MAL-2026-12674","summary":"Malicious code in ded-ps-events-ded-ps-events-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (38b1237ac35f64b35ae902019d79b84aeb8eacafc07339fcbca0de866dc6b797)\nindex.js unconditionally requires./setup.js on load. setup.js assembles hostnames at runtime via Array.join(\"\") to hide them from static scanners, resolving to four Cloudflare Workers endpoints (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS-TXT chunked fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. It selects a platform-specific path (/pkg/package, /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe), downloads the binary over HTTPS, writes it to /var/tmp or the Windows temp directory under a disguised name (dotnet_diag_\u003chex\u003e.exe or.cache_\u003chex\u003e), chmods 0o755, and spawns it detached via /bin/sh -c or cmd with.unref(). No hash or signature verification is performed, the endpoints are unrelated to the package's stated purpose (an event-bus framework), and a cooldown flag is written for persistence. Importing this package auto-executes attacker-controlled native code on the installer's machine.\n","modified":"2026-08-05T14:36:20.003974433Z","published":"2026-08-05T13:56:10Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.4.2"],"id":"IN-MAL-2026-015099","import_time":"2026-08-05T14:20:01.922234825Z","modified_time":"2026-08-05T13:56:10Z","sha256":"38b1237ac35f64b35ae902019d79b84aeb8eacafc07339fcbca0de866dc6b797"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ded-ps-events-ded-ps-events-core/v/35.4.2"}],"affected":[{"package":{"name":"ded-ps-events-ded-ps-events-core","ecosystem":"npm","purl":"pkg:npm/ded-ps-events-ded-ps-events-core"},"versions":["35.4.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ded-ps-events-ded-ps-events-core/MAL-2026-12674.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"29a1a59a06a6701c4bb09be5c6175415f66bf663328092d4fb5ca8982f7712483b2efc","path":"setup.js","sha256":"6ec47bc728b4fb3799a83bb36b5b80228a8c2e30158c68391dd6e81b4e6b89c7"}],"package_integrity":[{"filename":"ded-ps-events-ded-ps-events-core-35.4.2.tgz","hashes":{"sha512_sri":"sha512-Q48uMPiI6iYxjhbKx7kNfVPNNKSZepOpbCKOPs5DPF/zCW3L4+SftYUI+Oz9SeeXRzCR6VRs5TLd8FkmZe2jWA==","sha1":"74b8dfc5941c86ab24092662da434e957b18e12d"}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}