MAL-2026-12693
Dashboard / Malicious Package / MAL-2026-12693
MAL-2026-12693
Summary: Malicious code in devplatform-api-v1-endpoint (npm)
Details: Source: amazon-inspector (f2ed0defa1fbae571985664baae47d89d796f943b249115eb73a38edce04fb6c) On require, _adapter.js selects a platform-specific asset path and fetches an executable from string-split-obfuscated hosts under oob-worker.cf10*-*.workers.dev, falling back to base64-encoded payload chunks reassembled from DNS TXT queries against *.dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru). The fetched bytes are written to /var/tmp or %TEMP% under cover-story filenames (.cache_<hex>, dotnet_diag_<hex>.exe), chmod 0755, and spawned detached via /bin/sh -c or cmd /c start /b, with no hash or signature verification. A persistence marker (.analytics_state) with a ~6.4h freshness window throttles repeat activity. The delivery mechanism has no relation to the package's advertised SDK purpose, and the C2 host strings are reconstructed at runtime from split fragments via.join('') to defeat static analysis.
Affected packages
Package
Name: devplatform-api-v1-endpoint
Purl: pkg:npm/devplatform-api-v1-endpoint
Affected ranges
Type: N/A
Events:
