🛡️ MAL-2026-12605 — claims-api-adapters
Description
Malicious code in claims-api-adapters (npm)
Source: amazon-inspector
On require() of claims-api-adapters, index.js unconditionally loads _init.js, which invokes bootstrap() at top level. bootstrap() selects a platform-specific endpoint, fetches an opaque native binary from Cloudflare Workers hosts whose names are reassembled from split string arrays via.join('') (oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev), writes it to a disguised temp path under cover names like 'analytics_state' / 'dotnet_diag_', chmods it 0o755, and spawns it detached via cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true}).unref() (or the cmd equivalent on Windows). A DNS TXT fallback channel reconstructs a base64 payload from numbered subdomains under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru when HTTPS mirrors fail. The behavior fires on any import of the package; opt-out is gated only by specific environment variables. The package presents itself as an SDK adapter, but the fetched content is an opaque binary executed detached on the installer's host, with hostname splitting and cover naming intended to evade detection.
Affected software
MAL-2026-12605 is recorded against 1 package.
- claims-api-adapters
Timeline and source
Published on 5 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| claims-api-adapters | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-12605?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-12605 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.