Malicious code in claims-format-money (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (bc73b342ec9e00a543a54dcf8c212c8107638a9f2630ce32f239af5cc6a2d009) The package's index.js requires _bootstrap.js on import. _bootstrap.js reconstructs per-platform download URLs at runtime from split string fragments (assembling oob-worker.cf*-*.workers.dev hosts with DNS TXT fallback to *.wel1.ru), downloads an unpinned platform-specific binary, writes it to /var/tmp or %TEMP% under cover-story names such as dotnet_diag_<suffix>.exe and.cache_<suffix>, calls chmodSync(0o755), and spawns it detached via /bin/sh -c or cmd.exe with.unref(). A marker file.analytics_state, no-op log helper _l, and DISABLE_TELEMETRY/DO_NOT_TRACK checks frame the drop-and-execute as analytics telemetry, contradicting the package's stated purpose of money formatting. A second implementation of the same fetch->chmod->spawn primitive is shipped in lib/telemetry.js, using base64 chunk reassembly and identical DNS-based service discovery. The runtime-reconstructed hostnames, cover-story filenames, detached execution, and duplicate dropper paths are the fingerprint of a supply-chain binary dropper masquerading as a formatting utility.
Malicious code in claims-format-money (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (bc73b342ec9e00a543a54dcf8c212c8107638a9f2630ce32f239af5cc6a2d009) The package's index.js requires _bootstrap.js on import. _bootstrap.js reconstructs per-platform download URLs at runtime from split string fragments (assembling oob-worker.cf*-*.workers.dev hosts with DNS TXT fallback to *.wel1.ru), downloads an unpinned platform-specific binary, writes it to /var/tmp or %TEMP% under cover-story names such as dotnet_diag_<suffix>.exe and.cache_<suffix>, calls chmodSync(0o755), and spawns it detached via /bin/sh -c or cmd.exe with.unref(). A marker file.analytics_state, no-op log helper _l, and DISABLE_TELEMETRY/DO_NOT_TRACK checks frame the drop-and-execute as analytics telemetry, contradicting the package's stated purpose of money formatting. A second implementation of the same fetch->chmod->spawn primitive is shipped in lib/telemetry.js, using base64 chunk reassembly and identical DNS-based service discovery. The runtime-reconstructed hostnames, cover-story filenames, detached execution, and duplicate dropper paths are the fingerprint of a supply-chain binary dropper masquerading as a formatting utility.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12618
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735734bf8831d53913d199
Added to database: 08/05/2026, 15:31:00 UTC
Last updated: 08/05/2026, 15:31:00 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.