{"id":"MAL-2026-13205","summary":"Malicious code in eacq-acq-menu (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ae7929c06f789a6fc910fd4ce4697fd5d32f06b55a0c9b5e406110f90676c239)\nOn require() of the package, index.js loads _adapter.js which unconditionally executes a setup routine that fetches a platform-specific binary from runtime-reconstructed hosts (Cloudflare workers.dev subdomains such as oob-worker.cf10x-baf.workers.dev and *.dl.wel1.ru domains including sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), writes it to /tmp or %TEMP% under cover-story filenames (.cache_\u003chex\u003e, dotnet_diag_\u003chex\u003e.exe), chmods it 0755, and spawns it detached via spawn(\"/bin/sh\") or spawn(\"cmd\"). Destination hostnames are assembled by.join(\"\") of split substrings to defeat static string scanning, and a dnsChunked() routine reassembles a base64 payload from numbered TXT DNS records (c.\u003cdomain\u003e, 0.\u003cdomain\u003e, 1.\u003cdomain\u003e,...) as a fallback delivery channel. The package advertises itself as a menu-provider library and performs no such function; the only observable effect of installing/importing it is delivery and execution of an opaque remote binary on the installer's host.\n","modified":"2026-08-05T15:53:12.545154095Z","published":"2026-08-05T15:08:18Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.2.1"],"id":"IN-MAL-2026-015581","import_time":"2026-08-05T15:19:59.049851607Z","modified_time":"2026-08-05T15:08:18Z","sha256":"ae7929c06f789a6fc910fd4ce4697fd5d32f06b55a0c9b5e406110f90676c239"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/eacq-acq-menu/v/35.2.1"}],"affected":[{"package":{"name":"eacq-acq-menu","ecosystem":"npm","purl":"pkg:npm/eacq-acq-menu"},"versions":["35.2.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"86a1539b026960184bb0d7e4861b8816f65bf6633781c684fbac69944f7752482b2efc","path":"_adapter.js","sha256":"9e6e8986fb7ba75ea2da8170b63d41e64b16e41e8f0d12631900f804ac433230"}],"package_integrity":[{"filename":"eacq-acq-menu-35.2.1.tgz","hashes":{"sha512_sri":"sha512-RbJhJgrhCzzypjKEWWA0UEv4+JpHMVQLsQjgWb4lNqRksBimnywY2gGO7H41HJcGE7CD8StTAMZ/PetnqI4QSA==","sha1":"0dd3e0620538a018276d190112450752130f23e2"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/eacq-acq-menu/MAL-2026-13205.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}