claims-jira-service @35.8.3
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12627
Ecosystem
npm
Summary
On require('claims-jira-service'), index.js loads _ext.js which downloads a platform-specific executable from author-controlled hosts assembled at runtime by Array.join string-splitting (oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev) with a DNS TXT record fallback under *.dl.wel1.ru. The fetched bytes are written to a temp directory under disguised names (.cache_<hex>, dotnet_diag_<hex>.exe), chmod 0755, and spawned detached via /bin/sh -c or cmd. A stamp file with a benign name (.analytics_state) is used to throttle re-execution. Hostnames and payload paths are split across string arrays to defeat static analysis, and DNS-TXT chunking is used as a covert transport channel.
Source: amazon-inspector (666343795502690c0582b4b73652c215ad8f5025ca586d255e94910e8dd59744)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.