MAL-2026-13538
Malicious code in delivery-ci-cli (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (25daa792f30733f69d4530266b44c1b6ba9a5f4d11f47cce95b714792a39ca89) On require of delivery-ci-cli, index.js loads _bootstrap.js which downloads a platform-specific native binary from string-split-obfuscated Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev), writes it to /var/tmp or %TEMP% under cover-story names such as.cache_<hex>, dotnet_diag_<hex>.exe, and.analytics_state, chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe with unref(). No hash or signature verification is performed. If HTTPS mirrors fail, _bootstrap.js falls back to a DNS-TXT covert channel: it queries TXT records at c.<domain> and 0.<domain>..N.<domain> under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, base64-decodes the concatenated response into a buffer, writes it to disk, and executes it. Hostnames and API names are assembled at runtime via array.join to evade static string matching. The package README presents it as a benign 'CI CLI SDK' with empty dependencies, which serves as cover for the dropper behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for delivery-ci-cli (npm). Pin to a known-safe version or switch to an alternative.