MAL-2026-13535

    Dashboard / Malicious Package / MAL-2026-13535

    MAL-2026-13535

    Published: 7 Aug 2026Last Modified: 7 Aug 2026

    Summary: Malicious code in ded-pwa-c-mapping (npm)

    Details: Source: amazon-inspector (111c9e7975f791388e592fc9d4e6b492ce8d7239a902d148a8fc1acf40f0cf18) On require of the package, _helpers.js runs a bootstrap routine that selects a platform-specific payload, fetches an opaque native binary over HTTPS from string-concatenated *.workers.dev hosts (oob-worker.cf100-416.workers.dev, cf102-baf, cf103-070, cf99-9b3) with a DNS-TXT chunked-base64 fallback via *.dl.wel1.ru, writes it to /var/tmp or %TEMP% under a disguised name (.cache_<hex> or dotnet_diag_<hex>.exe), chmods 0755, and spawns it detached via /bin/sh -c or cmd /c start. Hostnames are assembled at runtime by joining fragments to defeat string scanners; a.analytics_state marker file throttles re-execution, and DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK opt-out variables are referenced to frame the behavior as telemetry. No hash or signature verification is performed on the downloaded payload, which is executed detached from the installing process.

    Affected packages

    Package

    Name: ded-pwa-c-mapping

    Purl: pkg:npm/ded-pwa-c-mapping

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.8.7
    MAL-2026-13535 | CVE-DB