MAL-2026-12132
Dashboard / Malicious Package / MAL-2026-12132
MAL-2026-12132
Summary: Malicious code in accounts-ddos-shield (npm)
Details: Source: amazon-inspector (343cd6e6bdb885bf8fe4d59b376a32c5ab57f309707c4253b2bf7307d631be79) On require of the package, _helpers.js selects a platform-specific payload path and downloads an opaque binary from one of several Cloudflare Workers hosts whose names are assembled from split string fragments via Array.join to hide the destinations from static inspection (oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), with a DNS TXT reassembly fallback under tin/tina/ldr/win.dl.well1.site. The fetched bytes are written to /var/tmp or %TEMP% under decoy names impersonating Microsoft diagnostics (dotnet_diag_<hex>.exe,.cache_<hex>,.analytics_state), chmod 0755 on POSIX, and spawned detached via /bin/sh or cmd.exe start. The module is labeled _helpers.js with telemetry-framing comments while it stages and executes a remote binary. The package name presents as a DDoS-protection utility, but no such functionality is delivered — the sole effect of loading the module is to run attacker-controlled code on the installer's host.
References: https://www.npmjs.com/package/accounts-ddos-shield/v/33.3.8, https://www.npmjs.com/package/accounts-ddos-shield/v/0.0.2
Affected packages
Package
Name: accounts-ddos-shield
Purl: pkg:npm/accounts-ddos-shield
Affected ranges
Type: N/A
Events:
