-= Per source details. Do not edit below this line.=-
The package advertises itself as a REST client wrapper but its main entry (index.js) requires./setup on load. setup.js selects a platform-specific URL, downloads bytes over HTTPS from a rotating set of anonymous Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev), writes them to /tmp or %TEMP% under disguised names such as dotnetdiag<hex>.exe and.cache<hex>, chmods 0755, and spawns the file detached via /bin/sh -c or cmd. Hostnames and the childprocess module name are assembled at runtime from split-string fragments, and a stamp file in /tmp gates re-execution on a ~20000-second TTL. If the HTTPS mirrors fail, setup.js falls back to a DNS-TXT covert channel: it resolves TXT records under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, reassembles chunked base64 into a binary, drops it, and executes it. The delivered bytes are opaque and unrelated to any REST-client functionality, and the delivery infrastructure (anonymous workers.dev hosts, split-string hostname obfuscation, DNS-TXT egress bypass, /tmp staging with disguised filenames, detached spawn) is characteristic of a malware dropper.
{
"malicious-packages-origins": [
{
"sha256": "0c11d3c5993128f5cb1eafd05487aeb9f630aee5bdef132bcf3d4b07bdfebe3e",
"id": "IN-MAL-2026-015150",
"modified_time": "2026-08-05T14:04:07Z",
"source": "amazon-inspector",
"import_time": "2026-08-05T14:20:07.283238769Z",
"versions": [
"35.4.9"
]
}
]
}{
"evidence_files": [
{
"sha256": "67199b9108f6ff15d04407ce2e2dd5348bf9fd86ad2406269d438559be8ff40e",
"path": "setup.js",
"tlsh": "5bb1535a16aa70084bb0d7e0c7174816f66af6a33781c684f79c69845f7312483b2efc"
}
],
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-6hrsaCTyrEXFZ78Ht9vlFFoJaNMeefF7tuGM2yVQCbfGg8mOXxOWtFwJZwWTIod8YIB29H37NBco1tS0NBJfPw==",
"sha1": "97ff41a89dde3e60903ad173745349cd9bb996f0"
},
"filename": "claims-handle-api-response-35.4.9.tgz"
}
]
}
[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-handle-api-response/MAL-2026-12623.json"