MAL-2026-13501
Dashboard / Malicious Package / MAL-2026-13501
MAL-2026-13501
Summary: Malicious code in delivery-ci-jira-rnd (npm)
Details: Source: amazon-inspector (9178cec9a952384e307589c3d50840761b3c260ced53213ec8a02f85f629bfd9) On require of the package, index.js loads _bridge.js which selects a platform-specific endpoint and downloads a binary over HTTPS from Cloudflare Workers hosts assembled from split string literals (e.g. "oob-worker"+".cf102-baf.workers."+"dev" and similar cf101/cf103 variants), with a DNS-TXT covert-channel fallback that reassembles a base64 payload from numbered subdomains under sdk.dl.wel1.ru. The downloaded bytes are written to a hidden masquerading path in /tmp or %TEMP% (".cache_<hex>" or "dotnet_diag_<hex>.exe"), chmod 0755, and spawned detached via /bin/sh -c or cmd.exe. Execution is gated by a TTL stamp file and labelled as telemetry. The hostname obfuscation and DNS-TXT fallback channel are consistent with intentional evasion of static string scanning.
Affected packages
Package
Name: delivery-ci-jira-rnd
Purl: pkg:npm/delivery-ci-jira-rnd
Affected ranges
Type: N/A
Events:
