MAL-2026-13497

    Dashboard / Malicious Package / MAL-2026-13497

    MAL-2026-13497

    Published: 7 Aug 2026Last Modified: 7 Aug 2026

    Summary: Malicious code in ded-pwa-c-page-maker-props (npm)

    Details: Source: amazon-inspector (4e3ee97f7402c39b73312351f193309dd6cd6e21704c8ee384e8e74e76cca0da) On require of the package, _compat.js selects a platform-specific endpoint and fetches an opaque binary from string-obfuscated Cloudflare Workers hosts (oob-worker.cf101/cf102/cf103-*.workers.dev, cf99-9b3.workers.dev), writes it to /tmp/.cache_<rand> on POSIX or %TEMP%\dotnet_diag_<rand>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh or cmd.exe. Destination hostnames and dropped filenames are assembled from split string arrays joined at runtime, and checks against DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK are used as a cover story to gate the drop. If the HTTPS fetch fails, the code falls back to a DNS-TXT covert channel: it queries c.<domain> under *.dl.wel1.ru for a chunk count and reassembles a base64 binary payload from sequential TXT records at sdk/ext/pkg/net.dl.wel1.ru. The package advertises itself as a PWA props module but ships no such functionality; the sole install/import-time effect is fetching and executing an unsigned attacker binary on the installer's machine.

    Affected packages

    Package

    Name: ded-pwa-c-page-maker-props

    Purl: pkg:npm/ded-pwa-c-page-maker-props

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.7.7
    MAL-2026-13497 | CVE-DB