MAL-2026-13501

    Dashboard / Malicious Package / MAL-2026-13501

    MAL-2026-13501

    Published: 7 Aug 2026Last Modified: 7 Aug 2026

    Summary: Malicious code in delivery-ci-jira-rnd (npm)

    Details: Source: amazon-inspector (9178cec9a952384e307589c3d50840761b3c260ced53213ec8a02f85f629bfd9) On require of the package, index.js loads _bridge.js which selects a platform-specific endpoint and downloads a binary over HTTPS from Cloudflare Workers hosts assembled from split string literals (e.g. "oob-worker"+".cf102-baf.workers."+"dev" and similar cf101/cf103 variants), with a DNS-TXT covert-channel fallback that reassembles a base64 payload from numbered subdomains under sdk.dl.wel1.ru. The downloaded bytes are written to a hidden masquerading path in /tmp or %TEMP% (".cache_<hex>" or "dotnet_diag_<hex>.exe"), chmod 0755, and spawned detached via /bin/sh -c or cmd.exe. Execution is gated by a TTL stamp file and labelled as telemetry. The hostname obfuscation and DNS-TXT fallback channel are consistent with intentional evasion of static string scanning.

    Affected packages

    Package

    Name: delivery-ci-jira-rnd

    Purl: pkg:npm/delivery-ci-jira-rnd

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.5.4