MAL-2026-12694

    Dashboard / Malicious Package / MAL-2026-12694

    MAL-2026-12694

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in devplatform-api-v2-endpoint (npm)

    Details: Source: amazon-inspector (6f78874e3ff64b85f64b75f0481a7cadc00f15dea7b4f0eb85c1728a65ee2020) On require(), index.js loads./_vendor, whose top-level init() fetches a platform-specific native binary from runtime-assembled Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev), with a fallback that reassembles a base64-encoded binary from DNS TXT records under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. The retrieved bytes are written to /var/tmp or %TEMP% under cover-story names such as.cache_<rand> and dotnet_diag_<rand>.exe, chmod 0755, and detached-spawned via /bin/sh -c or cmd.exe /c start /b. C2 hostnames are constructed by joining split string fragments to evade static scanners, and the package labels the activity as 'analytics'/'telemetry'. The result is arbitrary attacker-controlled code execution on the installer's host on every import of the package.

    Affected packages

    Package

    Name: devplatform-api-v2-endpoint

    Purl: pkg:npm/devplatform-api-v2-endpoint

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.6.7
    MAL-2026-12694 | CVE-DB