MAL-2026-13514Malicious code in eacq-core (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | eacq-core | 35.8.1 |
{"modified":"2026-08-07T12:11:32Z","published":"2026-08-07T12:11:32Z","schema_version":"1.7.4","id":"MAL-2026-13514","summary":"Malicious code in eacq-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b500358c69db5b11d186a6656bd7e20b6ae98cf8f8b437af7b320d511f870761)\nOn require() of eacq-core, both _helpers.js and lib/telemetry.js download a platform-specific binary from Cloudflare Workers hosts assembled at runtime via string-splitting (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT fallback to *.dl.wel1.ru, write the bytes to /tmp/.cache_<rand> or %TEMP%\\dotnet_diag_<rand>.exe, chmod 0755 (via fs['chmod'+'Sync']), and spawn the file detached through '/bin/sh -c <path> &' or 'cmd /c start'. No hash or signature verification is performed and the destinations are unrelated to any legitimate publisher. child_process is loaded through require('child_'+'process') and hostnames are assembled via.join('') to evade static analysis. Cover-story comments framing the code as an 'Analytics SDK' with 'opt-out env vars' accompany the payload. The fetch-and-execute chain fires unconditionally at module load, giving whoever controls the Workers hosts arbitrary code execution on any machine that installs or imports this package.\n","affected":[{"package":{"ecosystem":"npm","name":"eacq-core"},"versions":["35.8.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_helpers.js","sha256":"7be3d58dc23259dce7a933f383d0d1225056079778a1e1b08fb8bb1f370eac36","tlsh":"12a1b65616fa30180692e5d8842f9816b49ff6533284d9d4fb4c76984feb27883b29fc"},{"path":"lib/telemetry.js","sha256":"f8388c6cc9b9acda8a03931fac9e285ce219aa9bf2c66419c011b9caf8d83dbe","tlsh":"5c73304966fb10214263b0685ebb40437635c4072a4aed5dba9c43ec9f8db3896f1fb9"}],"package_integrity":[{"filename":"eacq-core-35.8.1.tgz","hashes":{"sha1":"a2829990f759fbde4cde3a7d6cea0c8a99b459a8","sha512_sri":"sha512-Ry5pHb/Wdq6hBrFp51PbzwMvvWPZ2OWp3XHiHCbMiwRLF+psBnLevSr27S1IisaD/tCGTypGbi+e3QKCftiKEQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/eacq-core/v/35.8.1"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016876","import_time":"2026-08-07T12:23:25.38104546Z","modified_time":"2026-08-07T12:11:32Z","sha256":"b500358c69db5b11d186a6656bd7e20b6ae98cf8f8b437af7b320d511f870761","source":"amazon-inspector","versions":["35.8.1"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0