MAL-2026-12693

    Dashboard / Malicious Package / MAL-2026-12693

    MAL-2026-12693

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in devplatform-api-v1-endpoint (npm)

    Details: Source: amazon-inspector (f2ed0defa1fbae571985664baae47d89d796f943b249115eb73a38edce04fb6c) On require, _adapter.js selects a platform-specific asset path and fetches an executable from string-split-obfuscated hosts under oob-worker.cf10*-*.workers.dev, falling back to base64-encoded payload chunks reassembled from DNS TXT queries against *.dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru). The fetched bytes are written to /var/tmp or %TEMP% under cover-story filenames (.cache_<hex>, dotnet_diag_<hex>.exe), chmod 0755, and spawned detached via /bin/sh -c or cmd /c start /b, with no hash or signature verification. A persistence marker (.analytics_state) with a ~6.4h freshness window throttles repeat activity. The delivery mechanism has no relation to the package's advertised SDK purpose, and the C2 host strings are reconstructed at runtime from split fragments via.join('') to defeat static analysis.

    Affected packages

    Package

    Name: devplatform-api-v1-endpoint

    Purl: pkg:npm/devplatform-api-v1-endpoint

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.9.8
    MAL-2026-12693 | CVE-DB