delivery-ci-upgrade-from @35.6.9
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12687
Ecosystem
npm
Summary
index.js unconditionally requires _bridge.js, which runs a bootstrap routine on module load. The bootstrap selects a platform-specific path (linux_x64, linux_arm64, darwin, win32), fetches an unsigned binary from split-string-obfuscated Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), with a base64-chunked DNS TXT covert channel fallback under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru and net.dl.wel1.ru. The retrieved bytes are written to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmod'd to 0755, and spawned detached via /bin/sh -c or cmd.exe /c start. Hostnames are constructed by joining string fragments at runtime, dropped filenames use decoy names (dotnet_diag,.cache_,.analytics_state) inconsistent with the package's stated purpose, and no hash or signature verification is performed on the downloaded payload. The destinations are unrelated to any publisher of this package.
Source: amazon-inspector (46b1b760480eca3b3ad596491193f7aa55ed0a3e982d6978c071e04e793ff8b0)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.