{"id":"MAL-2026-13200","summary":"Malicious code in dp-owners (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (09f190519e55e1e9899983a76806e839baf855abf0a0120e83bcac5547405c09)\nOn require() of dp-owners, _init.js selects a platform-specific path, downloads a binary from hardcoded Cloudflare Workers hosts assembled via string-split concatenation (oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf101-adf.workers.dev) with a DNS TXT chunked-base64 fallback under *.dl.wel1.ru, writes the bytes to /var/tmp or the Windows TEMP directory under disguised names (.cache_\u003chex\u003e on POSIX, dotnet_diag_\u003chex\u003e.exe on Windows), chmods the file 0755, and spawns it detached via /bin/sh -c \"\u003cpath\u003e &\" or cmd.exe /c start /b. Hostnames are reconstructed from split arrays to defeat static string matching, dropped filenames impersonate system diagnostic tooling, and a /tmp/.analytics_state marker plus DISABLE_TELEMETRY/DO_NOT_TRACK gates provide a telemetry cover story around the code-execution behavior. The fetched bytes are unrelated to the package's stated pluggable-owners-interface purpose.\n","modified":"2026-08-05T15:53:10.686281477Z","published":"2026-08-05T15:07:43Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T15:19:58.854370587Z","modified_time":"2026-08-05T15:07:43Z","sha256":"09f190519e55e1e9899983a76806e839baf855abf0a0120e83bcac5547405c09","source":"amazon-inspector","versions":["35.2.6"],"id":"IN-MAL-2026-015577"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dp-owners/v/35.2.6"}],"affected":[{"package":{"name":"dp-owners","ecosystem":"npm","purl":"pkg:npm/dp-owners"},"versions":["35.2.6"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dp-owners/MAL-2026-13200.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"9c053fe66932c1b2c03ae289d6078d3515154a1d8a1b679069c6cca28410b152","tlsh":"f0a1979a16b6701987b09be48a174416f65bf6633380c194fbacb9894f76124c272dfc","path":"_init.js"}],"package_integrity":[{"filename":"dp-owners-35.2.6.tgz","hashes":{"sha1":"85a7a197d9afd715df40536acafd4480e4601bf6","sha512_sri":"sha512-Rj2tJqvYoXH497Uy28TDssc9AgyaaHQyg5/HBHBoKSYoIfZ5Ym2iJ0Nth6n1XnwUDcbKBchU+rTv55ZMJZvYMw=="}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}