{"schema_version":"1.8.0","id":"MAL-2026-12525","published":"2026-08-05T14:18:06Z","modified":"2026-08-05T14:34:57.122170558Z","summary":"Malicious code in cards-forms-clone-credit-clone (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3b4f08d76d45a73180470637c59e6f64755dcc8f24853b66140d014b1dcbbdf8)\nOn require() of cards-forms-clone-credit-clone, index.js loads _helpers.js which auto-invokes a setup routine that detects the host OS/arch, downloads a platform-specific binary from obfuscated Cloudflare Workers subdomains (hostnames assembled via string-split.join(\"\") to evade static inspection), with a DNS TXT record fallback that reassembles base64-encoded payload chunks from TXT records under.dl.wel1.ru subdomains (sdk/ext/pkg/net.dl.wel1.ru). The fetched bytes are written to /var/tmp or %TEMP% under disguised names (dotnet_diag_*.exe,.cache_*), chmod 0755, and executed detached via spawn(\"/bin/sh\",...) or cmd.exe /c start. No pinning, no signature or hash verification, and the fetched content is unrelated to any documented package purpose. The name mimics a legitimate-sounding forms/credit-card handling library; there is no such functionality in the code.\n","affected":[{"package":{"name":"cards-forms-clone-credit-clone","ecosystem":"npm","purl":"pkg:npm/cards-forms-clone-credit-clone"},"versions":["35.7.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_helpers.js","sha256":"71bc4b660423939ac0ffe6e4fe4362d94c0d630a3f167d1c85b83a4ec309b5a2","tlsh":"ddb1866b116670184b70dbf4ca175815f55bfa6373808694f79ca5885fb322482b2efc"}],"package_integrity":[{"filename":"cards-forms-clone-credit-clone-35.7.1.tgz","hashes":{"sha1":"111e99e1817466385d28ca4cec32223f17035cfe","sha512_sri":"sha512-x3O+H40rjyjUNUcyF4d5s85Usl8luyl3rT9nY+B4js41qcrnL7IJEJRxWXXBcO1LU/PSHAzDLVB+CYTrKABPJw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cards-forms-clone-credit-clone/MAL-2026-12525.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/cards-forms-clone-credit-clone/v/35.7.1"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015246","import_time":"2026-08-05T14:20:16.287841758Z","modified_time":"2026-08-05T14:18:06Z","sha256":"3b4f08d76d45a73180470637c59e6f64755dcc8f24853b66140d014b1dcbbdf8","source":"amazon-inspector","versions":["35.7.1"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}