-= Per source details. Do not edit below this line.=-
On require('claims-jira-service'), index.js loads ext.js which downloads a platform-specific executable from author-controlled hosts assembled at runtime by Array.join string-splitting (oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev) with a DNS TXT record fallback under *.dl.wel1.ru. The fetched bytes are written to a temp directory under disguised names (.cache, dotnet_diag_.exe), chmod 0755, and spawned detached via /bin/sh -c or cmd. A stamp file with a benign name (.analytics_state) is used to throttle re-execution. Hostnames and payload paths are split across string arrays to defeat static analysis, and DNS-TXT chunking is used as a covert transport channel.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-015141",
"import_time": "2026-08-05T14:20:06.249530336Z",
"modified_time": "2026-08-05T14:02:43Z",
"sha256": "666343795502690c0582b4b73652c215ad8f5025ca586d255e94910e8dd59744",
"source": "amazon-inspector",
"versions": [
"35.8.3"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "_ext.js",
"sha256": "21eeafcea8cfe5e3e60ea2541a841f347911d14f9bd38c816925f4b72f569af6",
"tlsh": "aea1a95b16a6b0088bb0dbe4c7274415f65be6633781c1c4fb9ca9985fb2124c272efc"
}
],
"package_integrity": [
{
"filename": "claims-jira-service-35.8.3.tgz",
"hashes": {
"sha1": "ac429e3e7f2609d6111c2cc9542e61ba32873a3f",
"sha512_sri": "sha512-krmsV86BumrSfpWbmdWpRROfHkVHO6rRRwKzJnq4TGx5zaaEKzZ4246Fv+iJa78XM3zxtSpiksdRpDky+W6hOQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claims-jira-service/MAL-2026-12627.json"