Malicious code in ded-pwa-c-cms (npm)
The npm package ded-pwa-c-cms version 35.9.9 contains malicious code that downloads and executes an opaque binary from obfuscated, author-controlled hosts. The binary is saved to temporary directories and executed detached from the main process, masquerading as a legitimate Microsoft diagnostic tool. Execution is conditionally gated by environment variables to evade detection. No integrity checks are performed on the downloaded payload, increasing risk of arbitrary code execution.
AI Analysis
Technical Summary
The ded-pwa-c-cms npm package (version 35.9.9) includes code in its index.js that loads a platform-specific script to download a binary payload over HTTPS from obfuscated Cloudflare Workers and other suspicious subdomains. The payload is reconstructed using a DNS-TXT fallback channel and saved to temporary locations on Unix or Windows systems with executable permissions. It is then spawned as a detached process, bypassing normal telemetry by checking environment variables such as DISABLE_TELEMETRY. The binary filename mimics a Microsoft diagnostic tool (dotnet_diag) to avoid suspicion. No hash or signature verification is performed on the downloaded payload, allowing arbitrary code execution controlled by the package author.
Potential Impact
This malicious package enables remote code execution on systems that install ded-pwa-c-cms version 35.9.9 by downloading and executing an unverified binary payload. The payload runs detached from the main process and can evade telemetry detection, potentially allowing attackers to maintain persistence, execute arbitrary commands, or perform other malicious activities under the guise of a legitimate tool.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using ded-pwa-c-cms version 35.9.9 and remove it from their environments. Avoid installing or running this package until a trusted, verified version is released. Monitor for any unusual processes named similarly to Microsoft diagnostic tools and restrict execution of untrusted binaries from temporary directories. Check vendor advisories or trusted security sources for updates on remediation.
Malicious code in ded-pwa-c-cms (npm)
Description
The npm package ded-pwa-c-cms version 35.9.9 contains malicious code that downloads and executes an opaque binary from obfuscated, author-controlled hosts. The binary is saved to temporary directories and executed detached from the main process, masquerading as a legitimate Microsoft diagnostic tool. Execution is conditionally gated by environment variables to evade detection. No integrity checks are performed on the downloaded payload, increasing risk of arbitrary code execution.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ded-pwa-c-cms npm package (version 35.9.9) includes code in its index.js that loads a platform-specific script to download a binary payload over HTTPS from obfuscated Cloudflare Workers and other suspicious subdomains. The payload is reconstructed using a DNS-TXT fallback channel and saved to temporary locations on Unix or Windows systems with executable permissions. It is then spawned as a detached process, bypassing normal telemetry by checking environment variables such as DISABLE_TELEMETRY. The binary filename mimics a Microsoft diagnostic tool (dotnet_diag) to avoid suspicion. No hash or signature verification is performed on the downloaded payload, allowing arbitrary code execution controlled by the package author.
Potential Impact
This malicious package enables remote code execution on systems that install ded-pwa-c-cms version 35.9.9 by downloading and executing an unverified binary payload. The payload runs detached from the main process and can evade telemetry detection, potentially allowing attackers to maintain persistence, execute arbitrary commands, or perform other malicious activities under the guise of a legitimate tool.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using ded-pwa-c-cms version 35.9.9 and remove it from their environments. Avoid installing or running this package until a trusted, verified version is released. Monitor for any unusual processes named similarly to Microsoft diagnostic tools and restrict execution of untrusted binaries from temporary directories. Check vendor advisories or trusted security sources for updates on remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13496
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a75f712bf8831d53984fbfb
Added to database: 08/07/2026, 15:17:38 UTC
Last enriched: 08/07/2026, 15:46:53 UTC
Last updated: 08/07/2026, 16:21:05 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.