Malicious code in dws-frontend-dws-frontend-core (npm)
The npm package dws-frontend-dws-frontend-core version 35.4.3 contains malicious code that downloads and executes a platform-specific binary from author-controlled external hosts. The binary is saved to disguised filenames on the local system and executed without integrity verification. The package attempts to evade detection by assembling hostnames dynamically and pretending to respect telemetry opt-out environment variables, though it actually performs remote binary execution.
AI Analysis
Technical Summary
The dws-frontend-dws-frontend-core npm package version 35.4.3 includes code that, upon require(), loads a support script which downloads a platform-specific binary over HTTPS from external author-controlled domains (oob-worker.cf1*.workers.dev and a DNS TXT-record fallback under c.*.dl.wel1.ru). The downloaded binary is saved to temporary locations with filenames disguised as dotfile caches or Microsoft.NET diagnostic binaries, given executable permissions, and executed detached via shell commands. The code uses a marker file to throttle repeated execution and falsely signals respect for telemetry opt-out environment variables, while actually performing unauthorized remote binary execution. No hash or signature verification is performed on the downloaded payload, and the destination hosts are not publisher-owned or registry-hosted, indicating a supply chain compromise or malicious package.
Potential Impact
This malicious package can execute arbitrary code on the host system by downloading and running a binary from attacker-controlled servers without integrity checks. This can lead to full system compromise, data theft, persistence, or further malware deployment. The disguised filenames and evasion techniques increase the difficulty of detection and removal.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove the affected version (=35.4.3) of dws-frontend-dws-frontend-core from their environments. Avoid installing or using this package version and monitor for any unauthorized binaries or suspicious processes spawned from temporary directories. Verify package integrity and source before installation. Check vendor advisories or npm security notices for updates or official fixes.
Malicious code in dws-frontend-dws-frontend-core (npm)
Description
The npm package dws-frontend-dws-frontend-core version 35.4.3 contains malicious code that downloads and executes a platform-specific binary from author-controlled external hosts. The binary is saved to disguised filenames on the local system and executed without integrity verification. The package attempts to evade detection by assembling hostnames dynamically and pretending to respect telemetry opt-out environment variables, though it actually performs remote binary execution.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The dws-frontend-dws-frontend-core npm package version 35.4.3 includes code that, upon require(), loads a support script which downloads a platform-specific binary over HTTPS from external author-controlled domains (oob-worker.cf1*.workers.dev and a DNS TXT-record fallback under c.*.dl.wel1.ru). The downloaded binary is saved to temporary locations with filenames disguised as dotfile caches or Microsoft.NET diagnostic binaries, given executable permissions, and executed detached via shell commands. The code uses a marker file to throttle repeated execution and falsely signals respect for telemetry opt-out environment variables, while actually performing unauthorized remote binary execution. No hash or signature verification is performed on the downloaded payload, and the destination hosts are not publisher-owned or registry-hosted, indicating a supply chain compromise or malicious package.
Potential Impact
This malicious package can execute arbitrary code on the host system by downloading and running a binary from attacker-controlled servers without integrity checks. This can lead to full system compromise, data theft, persistence, or further malware deployment. The disguised filenames and evasion techniques increase the difficulty of detection and removal.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove the affected version (=35.4.3) of dws-frontend-dws-frontend-core from their environments. Avoid installing or using this package version and monitor for any unauthorized binaries or suspicious processes spawned from temporary directories. Verify package integrity and source before installation. Check vendor advisories or npm security notices for updates or official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13203
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a738536bf8831d5394f0b8d
Added to database: 08/05/2026, 18:47:18 UTC
Last enriched: 08/05/2026, 19:12:56 UTC
Last updated: 08/05/2026, 19:12:56 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.