{"id":"MAL-2026-13279","summary":"Malicious code in docflow-cryptopro (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b838ab488feb43fe2b50d6cd00579d3c1528877ea84d935ca89d8d863528bd25)\nOn require of the package's main, _platform.js downloads an opaque platform-specific binary from obfuscated Cloudflare Workers subdomains (hostnames assembled from split string fragments such as ['oob-worke','r.cf102-baf.workers','.d','ev']) with a DNS-TXT covert-channel fallback that reassembles a base64 payload from numbered TXT records under c.*.dl.wel1.ru. The binary is written to a temp path under a decoy name (e.g. dotnet_diag_*.exe,.cache_*), chmod +x is applied on POSIX, and it is spawned detached via /bin/sh -c '\u003cpath\u003e &' or cmd.exe /c start /b. Execution is gated by an 'analytics_state' marker and opt-out env-var checks that function as cover for the drop. The advertised purpose is 'cryptographic primitives', which does not match downloading and executing an unverified native binary from workers.dev hosts. The package name (docflow-cryptopro) resembles the CryptoPro / КриптоПро brand family and is not affiliated with that vendor.\n","modified":"2026-08-05T16:50:31.230619826Z","published":"2026-08-05T15:28:41Z","database_specific":{"malicious-packages-origins":[{"versions":["35.1.6"],"id":"IN-MAL-2026-015713","import_time":"2026-08-05T16:13:35.240064881Z","modified_time":"2026-08-05T15:28:41Z","sha256":"b838ab488feb43fe2b50d6cd00579d3c1528877ea84d935ca89d8d863528bd25","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/docflow-cryptopro/v/35.1.6"}],"affected":[{"package":{"name":"docflow-cryptopro","ecosystem":"npm","purl":"pkg:npm/docflow-cryptopro"},"versions":["35.1.6"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha1":"f73dffdda61c09cb011d3979e06d3359673fb334","sha512_sri":"sha512-lHYVn/b2A8yojxGZPIgR7YrSLxKH/Mdo7kC6OUTBsfz5rBMGT63vKZzDoGviZzmMC9PPO1aEdaHMX4pDLa7lfA=="},"filename":"docflow-cryptopro-35.1.6.tgz"}],"evidence_files":[{"tlsh":"42a1a46a126660058bb0dbe1c7176415f55ae66337808294fb9ca5c81fb212483f2efc","path":"_platform.js","sha256":"fbf5ab15ee35eae0a426b0efe708c031fecec9954596574f718705a8da63b576"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/docflow-cryptopro/MAL-2026-13279.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}