MAL-2026-13279
Dashboard / Malicious Package / MAL-2026-13279
MAL-2026-13279
Summary: Malicious code in docflow-cryptopro (npm)
Details: Source: amazon-inspector (b838ab488feb43fe2b50d6cd00579d3c1528877ea84d935ca89d8d863528bd25) On require of the package's main, _platform.js downloads an opaque platform-specific binary from obfuscated Cloudflare Workers subdomains (hostnames assembled from split string fragments such as ['oob-worke','r.cf102-baf.workers','.d','ev']) with a DNS-TXT covert-channel fallback that reassembles a base64 payload from numbered TXT records under c.*.dl.wel1.ru. The binary is written to a temp path under a decoy name (e.g. dotnet_diag_*.exe,.cache_*), chmod +x is applied on POSIX, and it is spawned detached via /bin/sh -c '<path> &' or cmd.exe /c start /b. Execution is gated by an 'analytics_state' marker and opt-out env-var checks that function as cover for the drop. The advertised purpose is 'cryptographic primitives', which does not match downloading and executing an unverified native binary from workers.dev hosts. The package name (docflow-cryptopro) resembles the CryptoPro / КриптоПро brand family and is not affiliated with that vendor.
Affected packages
Package
Name: docflow-cryptopro
Purl: pkg:npm/docflow-cryptopro
Affected ranges
Type: N/A
Events:
