MAL-2026-12683
Dashboard / Malicious Package / MAL-2026-12683
MAL-2026-12683
Summary: Malicious code in delivery-ci-tech-holder (npm)
Details: Source: amazon-inspector (63eae2afeb5a45d70f1d217049ab813392464cc8fb099462c716b8573836ed6b) On require() of the package, index.js loads _support.js, which reconstructs hardcoded destinations from split string arrays (oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, with a DNS-TXT fallback via sdk.dl.wel1.ru), downloads a platform-specific binary, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd with stdio ignored and unref(). No hash or signature verification is performed, the destination hosts are unrelated to the package publisher, filenames impersonate legitimate system components (dotnet_diag,.cache_), and the string-split reassembly and DNS-TXT fallback channel are designed to evade static inspection. The fetched bytes are executed with the installer's privileges.
Affected packages
Package
Name: delivery-ci-tech-holder
Purl: pkg:npm/delivery-ci-tech-holder
Affected ranges
Type: N/A
Events:
