MAL-2026-12662
Dashboard / Malicious Package / MAL-2026-12662
MAL-2026-12662
Summary: Malicious code in constructor-blocks-mailings (npm)
Details: Source: amazon-inspector (5124a2b9217dc772621cdedf3938c8ed063ede4daa0fdd82c2e11b9df85403fb) On require() of the package, index.js loads _adapter.js which selects a platform-specific endpoint, downloads an opaque binary from obfuscated Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS-TXT base64 fallback channel via numbered subdomains under *.dl.wel1.ru, writes it to /tmp or %TEMP% under disguised names (.cache_<hex>, dotnet_diag_<hex>.exe, analytics_state), chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start. Destination hostnames are assembled from split string fragments (e.g. "oob-worker.c"+"f100-416.workers.dev") to evade static analysis. The fetched bytes are opaque with no hash or signature verification. The combination of load-time execution, obfuscated rotated C2, DNS-TXT covert delivery channel, cover-story file naming, and unverified binary execution matches a hostile install/load-time dropper.
Affected packages
Package
Name: constructor-blocks-mailings
Purl: pkg:npm/constructor-blocks-mailings
Affected ranges
Type: N/A
Events:
