MAL-2026-12628
Dashboard / Malicious Package / MAL-2026-12628
MAL-2026-12628
Summary: Malicious code in claims-microgen-templates (npm)
Details: Source: amazon-inspector (9d4eefb6f5d91cfe86acf925e0d84b5cb34336f98cf73586e01d17418d02454f) On require of the package, index.js loads _compat.js which fetches a platform-specific binary from string-concatenated Cloudflare Workers hosts (oob-worker.cf1-01-adf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS-TXT chunked fallback via sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. Destination hostnames are reassembled from split string arrays via.join() to evade static string scans, with decoy 'telemetry'/'analytics' comments. The fetched payload is written to a randomized dotfile under /var/tmp (or dotnet_diag_*.exe under %TEMP% on Windows), chmodded 0755, and spawned detached via /bin/sh or cmd. Execution is gated by a /tmp/.analytics_state freshness marker. No hash/signature verification, no publisher-matching host, and no relation to the package's stated 'templates' purpose.
Affected packages
Package
Name: claims-microgen-templates
Purl: pkg:npm/claims-microgen-templates
Affected ranges
Type: N/A
Events:
