MAL-2026-12701
Dashboard / Malicious Package / MAL-2026-12701
MAL-2026-12701
Summary: Malicious code in devplatform-cli-plugin-generator (npm)
Details: Source: amazon-inspector (e369efa925874a9e8d5b883567522eb39e0284122294d62a92358b0b937f256f) On require() of the package, index.js loads _bootstrap.js, which reconstructs a list of Cloudflare Workers hostnames from split string fragments (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev) and a DNS-TXT chunked-base64 fallback under *.dl.wel1.ru, downloads a platform-specific binary from these non-publisher hosts with no hash or signature verification, writes it to /var/tmp or %TEMP% under cover-story names (dotnet_diag_<hex>.exe,.cache_<hex>), chmods it 0o755, and spawns it detached in the background via cp.spawn("/bin/sh", ["-c", fp+" &"], {detached:true}) or the Windows cmd equivalent. A second file, lib/telemetry.js (81 KB), bundles the same dropper primitives under an "Analytics SDK" cover story with additional obfuscation (require("child_"+"process"), fs["chmod"+"Sync"], base64-chunk assembly), extending the attack surface. Split-string reconstruction of hostnames and API names is anti-analysis obfuscation inconsistent with legitimate telemetry, which places endpoints in plain configuration.
Affected packages
Package
Name: devplatform-cli-plugin-generator
Purl: pkg:npm/devplatform-cli-plugin-generator
Affected ranges
Type: N/A
Events:
