{"id":"MAL-2026-13124","summary":"Malicious code in ded-aa-liza-ded-aa-liza-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (074f0a8014fabe8bdb281c1c07180290bcff2b10d67d723f1c7917ea198d5c5a)\nOn require() of ded-aa-liza-ded-aa-liza-core, index.js loads _ext.js which downloads a platform-specific binary from hardcoded Cloudflare Workers endpoints (oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev) with a DNS TXT fallback channel to sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. Destination hostnames are assembled at runtime by joining fragmented substring arrays (e.g. [\"oob-wor\",\"ker.cf103-070.workers.de\",\"v\"].join(\"\")) rather than appearing as plain literals. The fetched payload is written to /var/tmp or %TEMP% under names disguised to mimic diagnostic tools (.cache_\u003chex\u003e, dotnet_diag_\u003chex\u003e.exe), made executable via fs.chmodSync(0o755), and spawned detached through /bin/sh -c or cmd. The package is advertised as foundational type definitions but performs no such function; the only import-time effect is dropping and executing an opaque remote binary on the installer's host.\n","modified":"2026-08-05T15:52:34.806611670Z","published":"2026-08-05T15:17:21Z","database_specific":{"malicious-packages-origins":[{"sha256":"074f0a8014fabe8bdb281c1c07180290bcff2b10d67d723f1c7917ea198d5c5a","source":"amazon-inspector","versions":["35.2.5"],"id":"IN-MAL-2026-015639","import_time":"2026-08-05T15:20:01.22984098Z","modified_time":"2026-08-05T15:17:21Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ded-aa-liza-ded-aa-liza-core/v/35.2.5"}],"affected":[{"package":{"name":"ded-aa-liza-ded-aa-liza-core","ecosystem":"npm","purl":"pkg:npm/ded-aa-liza-ded-aa-liza-core"},"versions":["35.2.5"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"1fe92c7cafe4dbfbcbdd440413afba60ff43d298f2b422615d965cddd36bb6b8","tlsh":"35a1a65a01a6a0198eb0d7e0c71b4816f65bf5633780c294f75ca5984f775248372efc","path":"_ext.js"}],"package_integrity":[{"hashes":{"sha1":"ef4f25a3f3016f9fec490669b605db7a653a9285","sha512_sri":"sha512-5TCvuCfVVgFeKMVB74wqNPbzGCSOFXfhNVyGevmuMbSo5tcSclfWZEt62pKW3xvJ1YXvhXkoKizbLiyyjCPfVg=="},"filename":"ded-aa-liza-ded-aa-liza-core-35.2.5.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ded-aa-liza-ded-aa-liza-core/MAL-2026-13124.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}