{"schema_version":"1.8.0","id":"MAL-2026-12676","published":"2026-08-05T13:55:51Z","modified":"2026-08-05T14:36:21.118953552Z","summary":"Malicious code in delivery-ci-microforms (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3ffef831e876b8114ebfd6559d38f34d2c559dd42263845899e45ee621aa15c7)\nOn require('delivery-ci-microforms'), index.js loads _support.js which selects a platform-specific endpoint whose hostname is reassembled at runtime from split string arrays, fetches an opaque binary from oob-worker.cf100-416.workers.dev, cf99-9b3.workers.dev, or cf102-baf.workers.dev, or falls back to a chunked base64 payload carried in DNS TXT records under *.dl.wel1.ru. The fetched bytes are written to /tmp or %TEMP% under deceptive names such as dotnet_diag_<hex>.exe and.cache_<hex>, chmod 0755, and spawned detached via cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true, stdio:'ignore'}) or spawn('cmd',...) on Windows. lib/telemetry.js additionally reassembles the 'child_process' module name from a split string ('child_' + 'process') to defeat static inspection, and the drop path is gated behind opt-out env checks (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) with an 'analytics' cover-story naming scheme. Installing or requiring the package auto-executes attacker-controlled code from ephemeral Cloudflare Workers hosts on the installer's machine.\n","affected":[{"package":{"name":"delivery-ci-microforms","ecosystem":"npm","purl":"pkg:npm/delivery-ci-microforms"},"versions":["35.3.5"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_support.js","sha256":"9c83d1891075e3b319f266ed26a430cc604122b8daeced3e0d49a401668a4c13","tlsh":"8ba1876617a930294bb09be4c7175416f65afa633780c184fa9ca9941f7611483b2dfc"}],"package_integrity":[{"filename":"delivery-ci-microforms-35.3.5.tgz","hashes":{"sha1":"1617cf9da1f514324c0e2db282d389a44a7bcb17","sha512_sri":"sha512-51fWp2xQp7g0kVHKILyNjjNFJovq13ptFsUF7dFOGI0L4w2MukxUSLyE8HYoILlcNnQzYvW92prSXyRLb0YGfA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/delivery-ci-microforms/MAL-2026-12676.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/delivery-ci-microforms/v/35.3.5"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015097","import_time":"2026-08-05T14:20:01.64554545Z","modified_time":"2026-08-05T13:55:51Z","sha256":"3ffef831e876b8114ebfd6559d38f34d2c559dd42263845899e45ee621aa15c7","source":"amazon-inspector","versions":["35.3.5"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}