MAL-2026-12686
Dashboard / Malicious Package / MAL-2026-12686
MAL-2026-12686
Summary: Malicious code in delivery-ci-upgrade-form (npm)
Details: Source: amazon-inspector (c49d0422f51d7d7937c6a2b133b12ac6f4c6f1b914f03e9a6ad558e1b0f09fce) index.js unconditionally requires./_runtime at module load. _runtime.js detects platform/arch and downloads an OS-specific binary (linux_x64, linux_arm64, darwin, win32) from string-split-obfuscated Cloudflare Worker hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS-TXT chunked fallback across sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The fetched payload is written to /tmp or %TEMP% under disguised names (.cache_<hex>, dotnet_diag_<hex>.exe), chmod'd to 0755, and spawned detached via /bin/sh -c or cmd.exe. A.analytics_state stamp file TTL-gates re-execution. lib/telemetry.js ships a parallel dropper (HttpTransport/ServiceDiscovery/WorkerHost/NativeProfiler) with base64-decoded chunks written to disk, chmod'd 0755, spawned via cp.spawn('/bin/sh', ['-c', filePath+' &']), and obfuscates the child_process import as require('child_' + 'process'). Destination hostnames and dangerous API names are reassembled from split-string arrays to defeat static analysis.
Affected packages
Package
Name: delivery-ci-upgrade-form
Purl: pkg:npm/delivery-ci-upgrade-form
Affected ranges
Type: N/A
Events:
