{"id":"MAL-2026-13207","summary":"Malicious code in eacq-api (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1f72372a4c98fc1b4f187839fabe1a0bf8f7d98c8250c06baebf129920474332)\nOn require() of eacq-api, index.js loads _compat.js which reconstructs C2 hostnames from string-split fragments (oob-worker.cf10{0,1,2,3}-*.workers.dev) and a DNS TXT chunked-base64 fallback channel over *.dl.wel1.ru subdomains (sdk/ext/pkg/net). getBinary() downloads a platform-specific opaque binary over HTTPS (or via the DNS TXT fallback), writes it to a disguised path under /tmp or %TEMP% such as dotnet_diag_\u003chex\u003e.exe or.cache_\u003chex\u003e, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe. Execution is gated only by a filesystem cooldown marker and env opt-out flags; there is no hash or signature verification of the fetched bytes despite a comment claiming SHA-256 checking. The delivery infrastructure (anonymous Cloudflare Workers hosts + a DNS TXT covert channel) is unrelated to any legitimate API-client purpose, and the endpoint reconstruction plus alternate DNS transport indicate deliberate evasion of static scanners.\n","modified":"2026-08-05T15:53:13.249129758Z","published":"2026-08-05T15:06:16Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015568","import_time":"2026-08-05T15:19:58.332468711Z","modified_time":"2026-08-05T15:06:16Z","sha256":"1f72372a4c98fc1b4f187839fabe1a0bf8f7d98c8250c06baebf129920474332","source":"amazon-inspector","versions":["35.6.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/eacq-api/v/35.6.1"}],"affected":[{"package":{"name":"eacq-api","ecosystem":"npm","purl":"pkg:npm/eacq-api"},"versions":["35.6.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"a3b4ae94172058752776462a9c0428b0dcd492e9","sha512_sri":"sha512-3Feze5+9s8DyjVZFgvxX5qgg5MXsH58Vd5ZHBOt260jv+MrvsxDZzYEMT9X4yvc1m0PyOCPeUCqCoEEVX1ZjZg=="},"filename":"eacq-api-35.6.1.tgz"}],"evidence_files":[{"path":"_compat.js","sha256":"9b3fb16e38726e1b60ae8a0c1a7e76ec958a7421ebb291dd1645d1cf2600fc49","tlsh":"b3a186aa1166701c8bb0d7e087175415fa5be6633380c6d4fb6ca9945fb712483b2dfc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/eacq-api/MAL-2026-13207.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}