MAL-2026-13498Malicious code in ded-pwa-ded-pwa-core (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | ded-pwa-ded-pwa-core | 35.6.3 |
{"modified":"2026-08-07T12:14:25Z","published":"2026-08-07T12:14:25Z","schema_version":"1.7.4","id":"MAL-2026-13498","summary":"Malicious code in ded-pwa-ded-pwa-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (97666216930384a372fdf45c3c6a5d744e61de4b8e5c01f82a6ffe5688b168e7)\nOn require('ded-pwa-ded-pwa-core'), index.js unconditionally loads _adapter.js, which selects a platform-specific target path (%TEMP%/dotnet_diag_<hex>.exe on Windows, /tmp/.cache_<hex> on POSIX), fetches an opaque binary over HTTPS from author-controlled Cloudflare Workers endpoints, writes it to disk, chmods 0755, and detached-spawns it via cp.spawn('/bin/sh', ['-c', fp+' &'], {detached:true}) or cmd. The destination hostnames are reconstructed at runtime from split-string arrays (e.g. ['oob-worker.cf100-416.workers.','dev'].join('') and ['sdk.','dl','.wel1','.r','u'].join('') yielding sdk.dl.wel1.ru) to evade static grepping, and identifier lookups such as require('child_'+'process') and fs['chmod'+'Sync'] are similarly split. A DNS-TXT chunked-base64 fallback via *.dl.wel1.ru is present. Staged filenames masquerade as.NET diagnostics tooling or hidden cache files, and DO_NOT_TRACK / ANALYTICS_OPT_OUT env checks provide a telemetry cover story despite the executed content being an opaque author-controlled binary with no version pinning and no hash verification. Installing or requiring the package results in arbitrary code execution on the installer's host.\n","affected":[{"package":{"ecosystem":"npm","name":"ded-pwa-ded-pwa-core"},"versions":["35.6.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_adapter.js","sha256":"16514f1a9f742642e7c4a61037a28f605fc136dc37c54b95578b28201998f68d","tlsh":"8da1a9aa12a670084bb0e7f4c71b5415f656f6633381c298fb5c69985f7712883b1efc"}],"package_integrity":[{"filename":"ded-pwa-ded-pwa-core-35.6.3.tgz","hashes":{"sha1":"eea9bdcb76dd4babd64cf42d7c43ae46e1b0cbf8","sha512_sri":"sha512-bncLlKmsyKP7gUyHMG/UOrr+1zslr7bNyw3speA+62A48zSsSt783jsctN7dXnUAWoET1elX6pQDrr73IV9SBQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ded-pwa-ded-pwa-core/v/35.6.3"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016896","import_time":"2026-08-07T12:23:26.211591351Z","modified_time":"2026-08-07T12:14:25Z","sha256":"97666216930384a372fdf45c3c6a5d744e61de4b8e5c01f82a6ffe5688b168e7","source":"amazon-inspector","versions":["35.6.3"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0