MAL-2026-12623

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-handle-api-response/MAL-2026-12623.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12623
Published
2026-08-05T14:04:07Z
Modified
2026-08-05T14:35:54.325235377Z
Summary
Malicious code in claims-handle-api-response (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (0c11d3c5993128f5cb1eafd05487aeb9f630aee5bdef132bcf3d4b07bdfebe3e)

The package advertises itself as a REST client wrapper but its main entry (index.js) requires./setup on load. setup.js selects a platform-specific URL, downloads bytes over HTTPS from a rotating set of anonymous Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev), writes them to /tmp or %TEMP% under disguised names such as dotnetdiag<hex>.exe and.cache<hex>, chmods 0755, and spawns the file detached via /bin/sh -c or cmd. Hostnames and the childprocess module name are assembled at runtime from split-string fragments, and a stamp file in /tmp gates re-execution on a ~20000-second TTL. If the HTTPS mirrors fail, setup.js falls back to a DNS-TXT covert channel: it resolves TXT records under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, reassembles chunked base64 into a binary, drops it, and executes it. The delivered bytes are opaque and unrelated to any REST-client functionality, and the delivery infrastructure (anonymous workers.dev hosts, split-string hostname obfuscation, DNS-TXT egress bypass, /tmp staging with disguised filenames, detached spawn) is characteristic of a malware dropper.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "0c11d3c5993128f5cb1eafd05487aeb9f630aee5bdef132bcf3d4b07bdfebe3e",
            "id": "IN-MAL-2026-015150",
            "modified_time": "2026-08-05T14:04:07Z",
            "source": "amazon-inspector",
            "import_time": "2026-08-05T14:20:07.283238769Z",
            "versions": [
                "35.4.9"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / claims-handle-api-response

Package

Name
claims-handle-api-response
View open source insights on deps.dev
Purl
pkg:npm/claims-handle-api-response

Affected ranges

Affected versions

35.*
35.4.9

Database specific

indicators
{
    "evidence_files": [
        {
            "sha256": "67199b9108f6ff15d04407ce2e2dd5348bf9fd86ad2406269d438559be8ff40e",
            "path": "setup.js",
            "tlsh": "5bb1535a16aa70084bb0d7e0c7174816f66af6a33781c684f79c69845f7312483b2efc"
        }
    ],
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-6hrsaCTyrEXFZ78Ht9vlFFoJaNMeefF7tuGM2yVQCbfGg8mOXxOWtFwJZwWTIod8YIB29H37NBco1tS0NBJfPw==",
                "sha1": "97ff41a89dde3e60903ad173745349cd9bb996f0"
            },
            "filename": "claims-handle-api-response-35.4.9.tgz"
        }
    ]
}
cwes
[
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-handle-api-response/MAL-2026-12623.json"