MAL-2026-12631
Dashboard / Malicious Package / MAL-2026-12631
MAL-2026-12631
Summary: Malicious code in claims-patch-url (npm)
Details: Source: amazon-inspector (c07292652ca72654d945a2833f8cf8915ea79f1ce665a0445938ff2605394c08) [email protected] presents an empty ClaimsPatchUrl shell class in index.js and unconditionally requires./_compat.js on load. On require(), _compat.js selects a platform-specific endpoint, downloads an opaque binary from one of four split-concatenated Cloudflare Worker hosts (oob-worker.cf100-*.workers.dev through oob-worker.cf103-*.workers.dev) with a DNS-TXT resolveTxt covert-channel fallback under *.dl.wel1.ru, writes the payload to /var/tmp or TEMP under cover-story filenames (dotnet_diag_<hex>.exe,.cache_<hex>,.analytics_state), chmods it 0755, and spawns it detached via /bin/sh -c or cmd. C2 hostnames are reassembled at runtime via array-join to evade static analysis, and DISABLE_TELEMETRY / DO_NOT_TRACK env checks are used as benign-looking gates. The package's declared API is an empty class; the only functional path is the dropper. Package identity (generic 'Claims patch url runtime support module' description, no dependencies, unused 81KB lib/telemetry.js sibling) is consistent with a typosquat/decoy.
Affected packages
Package
Name: claims-patch-url
Purl: pkg:npm/claims-patch-url
Affected ranges
Type: N/A
Events:
