MAL-2026-12634

    Dashboard / Malicious Package / MAL-2026-12634

    MAL-2026-12634

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in claims-payout-offer-domain (npm)

    Details: Source: amazon-inspector (b7e5ae73b4b2f79e2790e4c9f503a3f469166c8d5587f7e84ac6a09022d1617f) On require() of the package, index.js unconditionally loads _vendor.js, which selects an OS/arch-specific payload path and fetches an opaque binary over HTTPS from string-obfuscated Cloudflare Workers hosts (oob-worker.cf*-*.workers.dev, assembled at runtime via array-join to evade static analysis). A DNS-TXT covert-channel fallback reads a chunk count from c.dl.wel1.ru and reassembles base64-encoded bytes across numbered subdomains of dl.wel1.ru. The fetched bytes are written to /tmp or %TEMP% under disguised names (e.g. dotnet_diag_*.exe,.cache_*), chmod 0755, and spawned detached via /bin/sh -c or cmd. No pinning, hash check, or signature verification is performed, and the destinations are not the publisher's infrastructure.

    Affected packages

    Package

    Name: claims-payout-offer-domain

    Purl: pkg:npm/claims-payout-offer-domain

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.6.1
    MAL-2026-12634 | CVE-DB