MAL-2026-12694
Dashboard / Malicious Package / MAL-2026-12694
MAL-2026-12694
Summary: Malicious code in devplatform-api-v2-endpoint (npm)
Details: Source: amazon-inspector (6f78874e3ff64b85f64b75f0481a7cadc00f15dea7b4f0eb85c1728a65ee2020) On require(), index.js loads./_vendor, whose top-level init() fetches a platform-specific native binary from runtime-assembled Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev), with a fallback that reassembles a base64-encoded binary from DNS TXT records under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. The retrieved bytes are written to /var/tmp or %TEMP% under cover-story names such as.cache_<rand> and dotnet_diag_<rand>.exe, chmod 0755, and detached-spawned via /bin/sh -c or cmd.exe /c start /b. C2 hostnames are constructed by joining split string fragments to evade static scanners, and the package labels the activity as 'analytics'/'telemetry'. The result is arbitrary attacker-controlled code execution on the installer's host on every import of the package.
Affected packages
Package
Name: devplatform-api-v2-endpoint
Purl: pkg:npm/devplatform-api-v2-endpoint
Affected ranges
Type: N/A
Events:
