{"id":"MAL-2026-13514","summary":"Malicious code in eacq-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b500358c69db5b11d186a6656bd7e20b6ae98cf8f8b437af7b320d511f870761)\nOn require() of eacq-core, both _helpers.js and lib/telemetry.js download a platform-specific binary from Cloudflare Workers hosts assembled at runtime via string-splitting (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT fallback to *.dl.wel1.ru, write the bytes to /tmp/.cache_\u003crand\u003e or %TEMP%\\dotnet_diag_\u003crand\u003e.exe, chmod 0755 (via fs['chmod'+'Sync']), and spawn the file detached through '/bin/sh -c \u003cpath\u003e &' or 'cmd /c start'. No hash or signature verification is performed and the destinations are unrelated to any legitimate publisher. child_process is loaded through require('child_'+'process') and hostnames are assembled via.join('') to evade static analysis. Cover-story comments framing the code as an 'Analytics SDK' with 'opt-out env vars' accompany the payload. The fetch-and-execute chain fires unconditionally at module load, giving whoever controls the Workers hosts arbitrary code execution on any machine that installs or imports this package.\n","modified":"2026-08-07T12:35:17.704728936Z","published":"2026-08-07T12:11:32Z","database_specific":{"malicious-packages-origins":[{"versions":["35.8.1"],"id":"IN-MAL-2026-016876","import_time":"2026-08-07T12:23:25.38104546Z","modified_time":"2026-08-07T12:11:32Z","sha256":"b500358c69db5b11d186a6656bd7e20b6ae98cf8f8b437af7b320d511f870761","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/eacq-core/v/35.8.1"}],"affected":[{"package":{"name":"eacq-core","ecosystem":"npm","purl":"pkg:npm/eacq-core"},"versions":["35.8.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/eacq-core/MAL-2026-13514.json","indicators":{"evidence_files":[{"path":"_helpers.js","sha256":"7be3d58dc23259dce7a933f383d0d1225056079778a1e1b08fb8bb1f370eac36","tlsh":"12a1b65616fa30180692e5d8842f9816b49ff6533284d9d4fb4c76984feb27883b29fc"},{"tlsh":"5c73304966fb10214263b0685ebb40437635c4072a4aed5dba9c43ec9f8db3896f1fb9","path":"lib/telemetry.js","sha256":"f8388c6cc9b9acda8a03931fac9e285ce219aa9bf2c66419c011b9caf8d83dbe"}],"package_integrity":[{"filename":"eacq-core-35.8.1.tgz","hashes":{"sha1":"a2829990f759fbde4cde3a7d6cea0c8a99b459a8","sha512_sri":"sha512-Ry5pHb/Wdq6hBrFp51PbzwMvvWPZ2OWp3XHiHCbMiwRLF+psBnLevSr27S1IisaD/tCGTypGbi+e3QKCftiKEQ=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}