MAL-2026-12705

    Dashboard / Malicious Package / MAL-2026-12705

    MAL-2026-12705

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in devplatform-confirm-input (npm)

    Details: Source: amazon-inspector (68424c7a93599d9d6d9391e3236d1ebf1d88fdc590b9c20f1ee615295335e5e8) [email protected] is advertised as a 'confirm input adapter' but on require() executes _ext.js, which fetches a platform-specific binary from string-concatenation-obfuscated Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), writes it to a temp path disguised as dotnet_diag_*.exe or a hidden.cache_* file, chmods it 0755, and spawns it detached via cmd.exe or /bin/sh. If HTTPS fails, a DNS-TXT chunked base64 fallback channel over sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru retrieves the payload. C2 hostnames and DNS-fallback domains are split into token arrays and reassembled at runtime, and the dropper uses cover-story identifiers ('.analytics_state', 'dotnet_diag_', 'Graceful degradation') to evade static analysis. Installing or importing this package results in remote code execution on the installer's host under attacker-controlled bytes.

    Affected packages

    Package

    Name: devplatform-confirm-input

    Purl: pkg:npm/devplatform-confirm-input

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.9.8