-= Per source details. Do not edit below this line.=-
index.js (the package main) require()s setup.js, which schedules bootstrap() on process.nextTick, so the dropper fires on any require() of the package. bootstrap() loads lib/telemetry.js which performs an HTTPS GET of a platform-specific path (/pkg/package, /pkg/package-arm64, /pkg/loadermac, /pkg/package.exe) against a rotating list of Cloudflare Workers subdomains (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with DNS-based fallbacks tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site. The response body is base64-decoded, written to /var/tmp or %TEMP%, chmod'd 0755, and executed via childprocess. The childprocess import, fs.chmodSync call, os.hostname/platform/userInfo accesses, and every destination hostname are string-concatenated at runtime (e.g. require('child'+'process'), ['oob-wor','ker.cf',...].join('')) to defeat static scanners. setup.js additionally computes a SHA-256 install fingerprint from os.hostname(), os.userInfo().username, process.cwd(), process.version, and process.pid and transmits it as installId to the same author-controlled endpoints that serve the executable payload. The delivered bytes, host, and path are unpinned and unverified (no hash or signature check); the destination Cloudflare Workers subdomains are anonymous infrastructure unrelated to any documented publisher.
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T09:12:26Z",
"sha256": "1d5fb3f28b70d54d37aae4fd8c15993f16fcbb0f299be9d03d4e1ea4061447f2",
"import_time": "2026-08-05T09:28:28.305410934Z",
"id": "IN-MAL-2026-014589",
"versions": [
"6.1.9"
]
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T09:11:22Z",
"sha256": "255e8d66104d31a1ca47d126114d3de3f53dddc4e64245e082b8de260b8ab117",
"import_time": "2026-08-05T09:28:27.687590527Z",
"id": "IN-MAL-2026-014582",
"versions": [
"33.9.5"
]
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T09:12:19Z",
"id": "IN-MAL-2026-014588",
"import_time": "2026-08-05T09:28:28.20490381Z",
"sha256": "2a193f48dce179cc9b43bc16917f5a04d89975c3451ebd33f766545c1c168664",
"versions": [
"6.1.10"
]
},
{
"modified_time": "2026-08-05T09:11:46Z",
"source": "amazon-inspector",
"sha256": "3fabdd067f353338f2d90fb8d4f88fc193292a4cc0ab3eb7f1e9d423ab8050d9",
"import_time": "2026-08-05T09:28:27.964308669Z",
"id": "IN-MAL-2026-014585",
"versions": [
"0.0.2"
]
},
{
"modified_time": "2026-08-05T09:12:09Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-014587",
"import_time": "2026-08-05T09:28:28.127978949Z",
"sha256": "5ed2fd89bb41899a53fad711bddffe0dc346e5028564d642183163988422affd",
"versions": [
"6.1.11"
]
},
{
"modified_time": "2026-08-05T09:11:59Z",
"source": "amazon-inspector",
"sha256": "7100ff6e54a5eb1e19f0bf6bbffc72142541c8076aa3f68147528c0f8c4d8647",
"import_time": "2026-08-05T09:28:28.039178803Z",
"id": "IN-MAL-2026-014586",
"versions": [
"6.1.12"
]
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T09:11:39Z",
"id": "IN-MAL-2026-014584",
"import_time": "2026-08-05T09:28:27.88627414Z",
"sha256": "8f5f1a3314685236b0fef012e02924316945e12fce08151ee3c98dd905b31f42",
"versions": [
"12.8.5"
]
}
]
}{
"package_integrity": [
{
"filename": "a.poltoradnev-package-c-33.9.5.tgz",
"hashes": {
"sha512_sri": "sha512-XmpAruhpYNYbghBZohW0zttry1ZHdgHKbHbqHQstuAlxcJYtc028oxb+C+l3ptp9Xai8uBu67W+B+cZX+8TVsA==",
"sha1": "4962b6e716ce8683c9f624d397b14be713eef65c"
}
}
],
"evidence_files": [
{
"tlsh": "519164084ed525250298e3f9296a4447e89614537ac8f248ba4ff2589f98138877ffbe",
"sha256": "44d13ca192133d1e1bb3c0dad1695c5167c4284e9789163c5347c821f267653e",
"path": "setup.js"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/a.poltoradnev-package-c/MAL-2026-12127.json"
[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]