-= Per source details. Do not edit below this line.=-
The package's main entry auto-requires setup.js on load, which fetches a platform-specific executable from split-string-obfuscated Cloudflare Workers endpoints (oob-worker.cf102-baf.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev), writes it to /tmp or %TEMP% under a disguised name (.cache_ or dotnet_diag_.exe), chmods it 0755 on POSIX, and spawns it detached via /bin/sh -c or cmd.exe. If HTTPS delivery fails, setup.js reassembles a base64-encoded payload from DNS TXT records under *.dl.wel1.ru (sdk./ext./pkg./net.dl.wel1.ru) as a covert-channel fallback, decodes it, writes it to disk, and executes it. Network destinations and the child_process require are assembled at runtime from split string fragments, and the package is framed as an analytics/telemetry SDK. lib/telemetry.js ships a parallel write-chmod-spawn dropper with the same obfuscation pattern. Requiring or installing the package results in execution of an opaque attacker-controlled binary on the host.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-015104",
"import_time": "2026-08-05T14:20:02.377027473Z",
"modified_time": "2026-08-05T13:56:53Z",
"sha256": "c25a4c4f3672ed82aa59bcac3fff0c6eadcb3eb35add0f52155c4436cba62c52",
"source": "amazon-inspector",
"versions": [
"35.5.4"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "setup.js",
"sha256": "97a1d80b071af49862635ec4e168bf45af399fd6224adc813b6a74679fa4371a",
"tlsh": "5da1959a16aa31184b70d7e5c627441af55bf6633380d2c4fb6c65841f7312482b2efc"
},
{
"path": "lib/telemetry.js",
"sha256": "4fe6a4451f6d61882b3b6be09aec6c78ea9c2eec47a4332cc3e93aab06cb9d6a",
"tlsh": "04835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"
}
],
"package_integrity": [
{
"filename": "custom-plugins-request-factory-35.5.4.tgz",
"hashes": {
"sha1": "5c9dae3631c52fa3495221df8f3852934cb526ea",
"sha512_sri": "sha512-hldfbB32x21p/4rMQD/18RdBeRoDVWdZ1ZY1THP4lTA467sK3wIG4Lcd7X4Fo9x4tL2xZxUJaxyPuLofjjslsw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/custom-plugins-request-factory/MAL-2026-12668.json"