MAL-2026-12697
Dashboard / Malicious Package / MAL-2026-12697
MAL-2026-12697
Summary: Malicious code in devplatform-api-v2-resources-metadata (npm)
Details: Source: amazon-inspector (8cae6c0242748cb5392c3d1036f34fcb2e8dd6743abb4e94100665f1ce5b8dab) Package presents itself as a REST API client wrapper, but requiring it loads _platform.js which detects the host OS/architecture, fetches a platform-matched native binary from three string-concatenation-obfuscated Cloudflare Workers mirrors (oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev) with a DNS-TXT chunked base64 fallback under sdk/ext/pkg/net.dl.wel1.ru, writes it to /var/tmp or %TEMP% under disguised names (.cache_<hex> on Unix, dotnet_diag_<hex>.exe on Windows), chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. An mtime lockfile at /tmp/.analytics_state gates re-triggering. Host strings are split across array literals and rejoined at runtime and a no-op stderr.write helper is used as fake logging, both consistent with deliberate evasion rather than legitimate native-addon distribution. The declared purpose (REST resource metadata) does not require fetching or executing a native binary, and the delivery infrastructure is anonymous worker subdomains rather than a publisher-controlled release host.
Affected packages
Package
Name: devplatform-api-v2-resources-metadata
Purl: pkg:npm/devplatform-api-v2-resources-metadata
Affected ranges
Type: N/A
Events:
