Malicious code in hubert-document-actual-insurance-rules-am (npm)
The npm package 'hubert-document-actual-insurance-rules-am' version 20.5.6 contains malicious code that downloads and executes attacker-controlled binaries upon module load. It disguises this behavior as telemetry by using misleading identifiers and dynamically assembles hostnames to evade static analysis. The malicious binary is fetched from a rotating list of Cloudflare Workers hosts or via DNS-TXT fallback, saved to temporary directories, given execute permissions, and run detached on the host system.
AI Analysis
Technical Summary
The package 'hubert-document-actual-insurance-rules-am' version 20.5.6 includes a malicious payload in its index.js file, which loads a helper script that downloads a platform-specific executable from obfuscated Cloudflare Workers URLs or DNS-TXT records. This executable is saved to a temporary location with a disguised filename, permissioned for execution, and launched detached from the main process. The code uses misleading telemetry-related identifiers to mask its true intent as a dropper for attacker-controlled binaries, activating immediately when the module is loaded.
Potential Impact
This malicious package can lead to arbitrary code execution on any system that installs and loads it, potentially allowing attackers to run any code with the privileges of the user executing the package. This can result in system compromise, data theft, or further malware deployment. Because the malicious binary is fetched dynamically from attacker-controlled infrastructure, the payload can be changed or updated at any time.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately avoid installing or using version 20.5.6 of 'hubert-document-actual-insurance-rules-am'. Remove the package from any affected systems and audit for any signs of compromise. Monitor for updates from the package maintainer or npm registry for any official fixes or removals. Consider blocking the identified Cloudflare Workers domains and the DNS-TXT fallback domain at network boundaries to prevent the download of malicious binaries.
Malicious code in hubert-document-actual-insurance-rules-am (npm)
Description
The npm package 'hubert-document-actual-insurance-rules-am' version 20.5.6 contains malicious code that downloads and executes attacker-controlled binaries upon module load. It disguises this behavior as telemetry by using misleading identifiers and dynamically assembles hostnames to evade static analysis. The malicious binary is fetched from a rotating list of Cloudflare Workers hosts or via DNS-TXT fallback, saved to temporary directories, given execute permissions, and run detached on the host system.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The package 'hubert-document-actual-insurance-rules-am' version 20.5.6 includes a malicious payload in its index.js file, which loads a helper script that downloads a platform-specific executable from obfuscated Cloudflare Workers URLs or DNS-TXT records. This executable is saved to a temporary location with a disguised filename, permissioned for execution, and launched detached from the main process. The code uses misleading telemetry-related identifiers to mask its true intent as a dropper for attacker-controlled binaries, activating immediately when the module is loaded.
Potential Impact
This malicious package can lead to arbitrary code execution on any system that installs and loads it, potentially allowing attackers to run any code with the privileges of the user executing the package. This can result in system compromise, data theft, or further malware deployment. Because the malicious binary is fetched dynamically from attacker-controlled infrastructure, the payload can be changed or updated at any time.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately avoid installing or using version 20.5.6 of 'hubert-document-actual-insurance-rules-am'. Remove the package from any affected systems and audit for any signs of compromise. Monitor for updates from the package maintainer or npm registry for any official fixes or removals. Consider blocking the identified Cloudflare Workers domains and the DNS-TXT fallback domain at network boundaries to prevent the download of malicious binaries.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12390
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735746bf8831d53915a06e
Added to database: 08/05/2026, 15:31:18 UTC
Last enriched: 08/05/2026, 17:34:58 UTC
Last updated: 08/05/2026, 17:34:58 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.