-= Per source details. Do not edit below this line.=-
index.js unconditionally requires./setup.js on load. setup.js assembles hostnames at runtime via Array.join("") to hide them from static scanners, resolving to four Cloudflare Workers endpoints (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS-TXT chunked fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. It selects a platform-specific path (/pkg/package, /pkg/package-arm64, /pkg/loadermac, /pkg/package.exe), downloads the binary over HTTPS, writes it to /var/tmp or the Windows temp directory under a disguised name (dotnetdiag<hex>.exe or.cache<hex>), chmods 0o755, and spawns it detached via /bin/sh -c or cmd with.unref(). No hash or signature verification is performed, the endpoints are unrelated to the package's stated purpose (an event-bus framework), and a cooldown flag is written for persistence. Importing this package auto-executes attacker-controlled native code on the installer's machine.
{
"malicious-packages-origins": [
{
"sha256": "38b1237ac35f64b35ae902019d79b84aeb8eacafc07339fcbca0de866dc6b797",
"id": "IN-MAL-2026-015099",
"modified_time": "2026-08-05T13:56:10Z",
"import_time": "2026-08-05T14:20:01.922234825Z",
"source": "amazon-inspector",
"versions": [
"35.4.2"
]
}
]
}{
"evidence_files": [
{
"sha256": "6ec47bc728b4fb3799a83bb36b5b80228a8c2e30158c68391dd6e81b4e6b89c7",
"path": "setup.js",
"tlsh": "29a1a59a06a6701c4bb09be5c6175415f66bf663328092d4fb5ca8982f7712483b2efc"
}
],
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-Q48uMPiI6iYxjhbKx7kNfVPNNKSZepOpbCKOPs5DPF/zCW3L4+SftYUI+Oz9SeeXRzCR6VRs5TLd8FkmZe2jWA==",
"sha1": "74b8dfc5941c86ab24092662da434e957b18e12d"
},
"filename": "ded-ps-events-ded-ps-events-core-35.4.2.tgz"
}
]
}
[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ded-ps-events-ded-ps-events-core/MAL-2026-12674.json"