MAL-2026-12132

    Dashboard / Malicious Package / MAL-2026-12132

    MAL-2026-12132

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in accounts-ddos-shield (npm)

    Details: Source: amazon-inspector (343cd6e6bdb885bf8fe4d59b376a32c5ab57f309707c4253b2bf7307d631be79) On require of the package, _helpers.js selects a platform-specific payload path and downloads an opaque binary from one of several Cloudflare Workers hosts whose names are assembled from split string fragments via Array.join to hide the destinations from static inspection (oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), with a DNS TXT reassembly fallback under tin/tina/ldr/win.dl.well1.site. The fetched bytes are written to /var/tmp or %TEMP% under decoy names impersonating Microsoft diagnostics (dotnet_diag_<hex>.exe,.cache_<hex>,.analytics_state), chmod 0755 on POSIX, and spawned detached via /bin/sh or cmd.exe start. The module is labeled _helpers.js with telemetry-framing comments while it stages and executes a remote binary. The package name presents as a DDoS-protection utility, but no such functionality is delivered — the sole effect of loading the module is to run attacker-controlled code on the installer's host.

    Affected packages

    Package

    Name: accounts-ddos-shield

    Purl: pkg:npm/accounts-ddos-shield

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    33.3.8
    MAL-2026-12132 | CVE-DB