MAL-2026-12670

    Dashboard / Malicious Package / MAL-2026-12670

    MAL-2026-12670

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in dc-dc-core (npm)

    Details: Source: amazon-inspector (e706ce5be3f3c1cf779ad16844cea8737714c708fe739316bec4ff400b415139) On require('dc-dc-core'), index.js loads _support.js which fetches a platform-specific native binary from obfuscated Cloudflare worker hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev), writes it to a temp path under a disguised name (dotnet_diag_*.exe on Windows,.cache_* on Unix), chmods 0755, and spawns it detached via child_process.spawn (spawn('/bin/sh',...) or spawn('cmd',...)). A DNS-TXT fallback channel reassembles a payload by querying resolver domains sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru. Hostnames are constructed by joining split string fragments at runtime to evade static detection, and the module wraps the behavior in analytics/telemetry cover-story naming (DISABLE_TELEMETRY env gate, /tmp/.analytics_state TTL flag). The package name resembles legitimate scopes but ships an import-time dropper.

    Affected packages

    Package

    Name: dc-dc-core

    Purl: pkg:npm/dc-dc-core

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.3.3