MAL-2026-12528

    Dashboard / Malicious Package / MAL-2026-12528

    MAL-2026-12528

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in cards-forms-debit-clone (npm)

    Details: Source: amazon-inspector (7cfb99b5f4ad953f445a050a5cb70c26e477398cedef5406fdce1343887a6e38) On require(), index.js loads _shim.js which downloads a platform-specific binary from anonymous *.workers.dev subdomains (hostnames assembled at runtime by joining split string fragments to evade static matching), writes the bytes to /tmp or %TEMP% under disguised names (".cache_<hex>" on Unix, "dotnet_diag_<hex>.exe" on Windows), chmods 0755, and spawns the binary detached via child_process.spawn("/bin/sh") or spawn("cmd"). If HTTPS retrieval fails, a DNS TXT fallback channel against *.dl.wel1.ru reads a chunk count from c.<domain>, iterates N subdomains to reassemble a base64-encoded payload, and executes the decoded bytes. No signature or hash verification is performed, the fetched content is opaque, and the routine is labeled "telemetry" as a cover story with a nominal opt-out. The behavior fires on any import of the package.

    Affected packages

    Package

    Name: cards-forms-debit-clone

    Purl: pkg:npm/cards-forms-debit-clone

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.2.3