MAL-2026-12643
Dashboard / Malicious Package / MAL-2026-12643
MAL-2026-12643
Summary: Malicious code in claims-should-retry (npm)
Details: Source: amazon-inspector (dfeb9953f0f268a6f342f7c5b8d31292bf0f0855b736149d56df7eab1e119ebd) On require of the package, index.js loads _platform.js, which reconstructs destination hosts from split string arrays (e.g. Cloudflare Workers subdomains under oob-worker.cf*-*.workers.dev) via.join("") to hide them from static inspection, downloads a platform-specific binary, writes it to /tmp or %TEMP% under a misleading name (dotnet_diag_*.exe or.cache_*), chmods it 0755, and spawns it detached with stdio ignored via child_process spawn against /bin/sh or cmd. If HTTP fetch fails, a DNS-TXT covert-channel fallback enumerates numbered TXT records under reconstructed *.dl.wel1.ru subdomains, base64-decodes and concatenates them into an executable buffer that is written and executed the same way. A.analytics_state / analytics_state marker file suppresses re-execution, opt-out environment variables (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) provide a telemetry cover story, and a no-op logger overwrites console output to suppress traces. The package is advertised as a claims-retry library and has no relation to fetching or executing platform binaries.
Affected packages
Package
Name: claims-should-retry
Purl: pkg:npm/claims-should-retry
Affected ranges
Type: N/A
Events:
