{"id":"MAL-2026-13203","summary":"Malicious code in dws-frontend-dws-frontend-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7fb73f65c18cf45f29f533ef6b9ab1278412909686c0750018f9d35170ed39f2)\nOn require() of this package, index.js loads _support.js which downloads a platform-specific binary over HTTPS from author-controlled hosts under oob-worker.cf1*.workers.dev (with a DNS TXT-record base64 fallback under c.*.dl.wel1.ru). Destination hostnames are assembled via.join('') on split string fragments to evade static analysis. The fetched bytes are written to /var/tmp/.cache_\u003chex\u003e on Unix or %TEMP%\\dotnet_diag_\u003chex\u003e.exe on Windows — filenames disguised as a dotfile cache or a Microsoft.NET diagnostics binary — chmod 0755, and spawned detached via /bin/sh -c or cmd. A /tmp/.analytics_state marker file throttles re-execution, and the code pretends to honor DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK as a cover story despite the observed behavior being remote-binary execution rather than telemetry. No hash or signature verification is performed on the downloaded payload; the destination is not a publisher-owned or registry-hosted artifact.\n","modified":"2026-08-05T15:53:11.402369229Z","published":"2026-08-05T15:07:27Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T15:19:58.670679302Z","modified_time":"2026-08-05T15:07:27Z","sha256":"7fb73f65c18cf45f29f533ef6b9ab1278412909686c0750018f9d35170ed39f2","source":"amazon-inspector","versions":["35.4.3"],"id":"IN-MAL-2026-015575"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dws-frontend-dws-frontend-core/v/35.4.3"}],"affected":[{"package":{"name":"dws-frontend-dws-frontend-core","ecosystem":"npm","purl":"pkg:npm/dws-frontend-dws-frontend-core"},"versions":["35.4.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"c5b1a75a1266711c4bb0abe4871b8416f65bf66337c0c5c4fb9c98881fb212483b2efc","path":"_support.js","sha256":"8b17258b7a49297193bf16b4e2f055d3c28cd52975abba6e1b734cf8aa09e5e5"}],"package_integrity":[{"filename":"dws-frontend-dws-frontend-core-35.4.3.tgz","hashes":{"sha1":"54269b41286b5f9a8b554587306cf9debf4f7b71","sha512_sri":"sha512-RaLPvrC6QB/MugdnLLpAG6Yz9xLtce0w+9EIp/AIbHAQq3HsIkayfXMRDhcnH9UnYo+KiKwuJD56jqZQKEbAsg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dws-frontend-dws-frontend-core/MAL-2026-13203.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}