Malicious code in claims-use-callback-once (npm)
The npm package claims-use-callback-once version 35.6.7 contains malicious code that downloads and executes a payload from multiple hardcoded Cloudflare Workers hosts and a DNS TXT base64 fallback domain. The payload is saved under deceptive Microsoft-diagnostics-style filenames in temporary directories, given executable permissions, and executed detached from the main process. The package masquerades as a callback utility but includes no legitimate functionality and uses obfuscation techniques to evade static analysis. A parallel dropper implementation is disguised as an 'Analytics SDK'.
AI Analysis
Technical Summary
The claims-use-callback-once npm package version 35.6.7 is malicious. Upon requiring the package, it loads a shim that selects a platform-specific payload path and fetches an executable payload from several hardcoded Cloudflare Workers domains, with a DNS TXT base64 fallback over a suspicious domain. The payload is written to temporary directories with deceptive names resembling Microsoft diagnostics tools, permissions are set to executable (chmod 0755), and it is spawned detached via shell commands. The package uses runtime string assembly to evade static detection. Additionally, lib/telemetry.js contains a parallel dropper under the guise of an Analytics SDK. The package does not provide any legitimate callback functionality despite its name.
Potential Impact
The malicious package can execute arbitrary code on the host system by downloading and running an external payload with elevated permissions. This can lead to full system compromise, persistence, and potential further malicious activity. The obfuscation and use of multiple delivery mechanisms make detection and prevention more difficult.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. The best mitigation is to avoid using claims-use-callback-once version 35.6.7 and remove it from any environments where it is installed. Use trusted package sources and verify package integrity before installation. Monitor for suspicious activity related to execution of unexpected binaries in temporary directories.
Malicious code in claims-use-callback-once (npm)
Description
The npm package claims-use-callback-once version 35.6.7 contains malicious code that downloads and executes a payload from multiple hardcoded Cloudflare Workers hosts and a DNS TXT base64 fallback domain. The payload is saved under deceptive Microsoft-diagnostics-style filenames in temporary directories, given executable permissions, and executed detached from the main process. The package masquerades as a callback utility but includes no legitimate functionality and uses obfuscation techniques to evade static analysis. A parallel dropper implementation is disguised as an 'Analytics SDK'.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The claims-use-callback-once npm package version 35.6.7 is malicious. Upon requiring the package, it loads a shim that selects a platform-specific payload path and fetches an executable payload from several hardcoded Cloudflare Workers domains, with a DNS TXT base64 fallback over a suspicious domain. The payload is written to temporary directories with deceptive names resembling Microsoft diagnostics tools, permissions are set to executable (chmod 0755), and it is spawned detached via shell commands. The package uses runtime string assembly to evade static detection. Additionally, lib/telemetry.js contains a parallel dropper under the guise of an Analytics SDK. The package does not provide any legitimate callback functionality despite its name.
Potential Impact
The malicious package can execute arbitrary code on the host system by downloading and running an external payload with elevated permissions. This can lead to full system compromise, persistence, and potential further malicious activity. The obfuscation and use of multiple delivery mechanisms make detection and prevention more difficult.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. The best mitigation is to avoid using claims-use-callback-once version 35.6.7 and remove it from any environments where it is installed. Use trusted package sources and verify package integrity before installation. Monitor for suspicious activity related to execution of unexpected binaries in temporary directories.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12647
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a735735bf8831d539141d73
Added to database: 08/05/2026, 15:31:01 UTC
Last enriched: 08/05/2026, 16:18:47 UTC
Last updated: 09/07/2026, 22:19:17 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.