claims-handle-api-response @35.4.9
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12623
Ecosystem
npm
Summary
The package advertises itself as a REST client wrapper but its main entry (index.js) requires./setup on load. setup.js selects a platform-specific URL, downloads bytes over HTTPS from a rotating set of anonymous Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev), writes them to /tmp or %TEMP% under disguised names such as dotnet_diag_<hex>.exe and.cache_<hex>, chmods 0755, and spawns the file detached via /bin/sh -c or cmd. Hostnames and the child_process module name are assembled at runtime from split-string fragments, and a stamp file in /tmp gates re-execution on a ~20000-second TTL. If the HTTPS mirrors fail, setup.js falls back to a DNS-TXT covert channel: it resolves TXT records under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, reassembles chunked base64 into a binary, drops it, and executes it. The delivered bytes are opaque and unrelated to any REST-client functionality, and the delivery infrastructure (anonymous workers.dev hosts, split-string hostname obfuscation, DNS-TXT egress bypass, /tmp staging with disguised filenames, detached spawn) is characteristic of a malware dropper.
Source: amazon-inspector (0c11d3c5993128f5cb1eafd05487aeb9f630aee5bdef132bcf3d4b07bdfebe3e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.