MAL-2026-12701

    Dashboard / Malicious Package / MAL-2026-12701

    MAL-2026-12701

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in devplatform-cli-plugin-generator (npm)

    Details: Source: amazon-inspector (e369efa925874a9e8d5b883567522eb39e0284122294d62a92358b0b937f256f) On require() of the package, index.js loads _bootstrap.js, which reconstructs a list of Cloudflare Workers hostnames from split string fragments (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev) and a DNS-TXT chunked-base64 fallback under *.dl.wel1.ru, downloads a platform-specific binary from these non-publisher hosts with no hash or signature verification, writes it to /var/tmp or %TEMP% under cover-story names (dotnet_diag_<hex>.exe,.cache_<hex>), chmods it 0o755, and spawns it detached in the background via cp.spawn("/bin/sh", ["-c", fp+" &"], {detached:true}) or the Windows cmd equivalent. A second file, lib/telemetry.js (81 KB), bundles the same dropper primitives under an "Analytics SDK" cover story with additional obfuscation (require("child_"+"process"), fs["chmod"+"Sync"], base64-chunk assembly), extending the attack surface. Split-string reconstruction of hostnames and API names is anti-analysis obfuscation inconsistent with legitimate telemetry, which places endpoints in plain configuration.

    Affected packages

    Package

    Name: devplatform-cli-plugin-generator

    Purl: pkg:npm/devplatform-cli-plugin-generator

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.3.5