Malicious code in claims-format-masked-phone-number (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (fa7c82af39243a3c62938129f431e38e106ddc3209511d8d8389995bc36590a6) The package advertises phone-number masking but on every require() loads _polyfill.js, which selects an OS/arch-specific asset and fetches an opaque native binary from one of four hardcoded Cloudflare Workers subdomains (oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev). The hostnames are assembled at runtime via.join() over fragmented string arrays to defeat static scanners. The fetched bytes are written to /var/tmp/.cache_<rand> or %TEMP%\dotnet_diag_<rand>.exe, chmod 0755, and detached via /bin/sh -c "<path> &" or cmd /c start with no hash or signature verification. A fallback channel issues DNS TXT queries against sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, concatenates the chunked TXT responses, and base64-decodes them into an executable buffer that is dropped and run the same way. Cover-story elements (file names like.analytics_state and dotnet_diag_*.exe, comments about telemetry opt-out, DISABLE_TELEMETRY/DO_NOT_TRACK env checks) do not match the package's stated purpose and no binary distribution is part of a phone-number masking library.
Malicious code in claims-format-masked-phone-number (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (fa7c82af39243a3c62938129f431e38e106ddc3209511d8d8389995bc36590a6) The package advertises phone-number masking but on every require() loads _polyfill.js, which selects an OS/arch-specific asset and fetches an opaque native binary from one of four hardcoded Cloudflare Workers subdomains (oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev). The hostnames are assembled at runtime via.join() over fragmented string arrays to defeat static scanners. The fetched bytes are written to /var/tmp/.cache_<rand> or %TEMP%\dotnet_diag_<rand>.exe, chmod 0755, and detached via /bin/sh -c "<path> &" or cmd /c start with no hash or signature verification. A fallback channel issues DNS TXT queries against sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, concatenates the chunked TXT responses, and base64-decodes them into an executable buffer that is dropped and run the same way. Cover-story elements (file names like.analytics_state and dotnet_diag_*.exe, comments about telemetry opt-out, DISABLE_TELEMETRY/DO_NOT_TRACK env checks) do not match the package's stated purpose and no binary distribution is part of a phone-number masking library.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12617
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735734bf8831d53913d1b7
Added to database: 08/05/2026, 15:31:00 UTC
Last updated: 08/05/2026, 15:39:18 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.