MAL-2026-12528
Dashboard / Malicious Package / MAL-2026-12528
MAL-2026-12528
Summary: Malicious code in cards-forms-debit-clone (npm)
Details: Source: amazon-inspector (7cfb99b5f4ad953f445a050a5cb70c26e477398cedef5406fdce1343887a6e38) On require(), index.js loads _shim.js which downloads a platform-specific binary from anonymous *.workers.dev subdomains (hostnames assembled at runtime by joining split string fragments to evade static matching), writes the bytes to /tmp or %TEMP% under disguised names (".cache_<hex>" on Unix, "dotnet_diag_<hex>.exe" on Windows), chmods 0755, and spawns the binary detached via child_process.spawn("/bin/sh") or spawn("cmd"). If HTTPS retrieval fails, a DNS TXT fallback channel against *.dl.wel1.ru reads a chunk count from c.<domain>, iterates N subdomains to reassemble a base64-encoded payload, and executes the decoded bytes. No signature or hash verification is performed, the fetched content is opaque, and the routine is labeled "telemetry" as a cover story with a nominal opt-out. The behavior fires on any import of the package.
Affected packages
Package
Name: cards-forms-debit-clone
Purl: pkg:npm/cards-forms-debit-clone
Affected ranges
Type: N/A
Events:
