MAL-2026-12667
Dashboard / Malicious Package / MAL-2026-12667
MAL-2026-12667
Summary: Malicious code in csc-csc-core (npm)
Details: Source: amazon-inspector (0339e6587ac1d675e493fc3edc1e7d325982284f794a681327053e1131ce689c) On require of csc-csc-core, index.js loads _init.js which downloads a platform-specific binary from string-split obfuscated Cloudflare Workers hostnames (oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS TXT chunked fallback via *.dl.wel1.ru subdomains, writes it to /var/tmp or %TEMP% under a disguised name (e.g..cache_<hex>, dotnet_diag_<hex>.exe), chmods 0755, and spawns it detached via cp.spawn('/bin/sh',['-c', fp+' &'],{detached:true}).unref(). C2 hostnames and resolver domains are assembled at runtime from arrays of fragments to defeat static scanners. A /tmp cooldown marker and DO_NOT_TRACK opt-out are used to evade sandboxes. The README advertises the package as a 'base framework module' with no such behavior.
Affected packages
Package
Name: csc-csc-core
Purl: pkg:npm/csc-csc-core
Affected ranges
Type: N/A
Events:
