MAL-2026-12709

    Dashboard / Malicious Package / MAL-2026-12709

    MAL-2026-12709

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in devplatform-di (npm)

    Details: Source: amazon-inspector (e3fd866e9abd20e9fa0c9ca40131d13b1ca98e2abbe73f53fd063581a65256d9) On require('devplatform-di'), index.js loads _compat.js which fetches a platform-specific executable from string-split-obfuscated hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev), with a base64-chunk DNS TXT fallback across sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The downloaded bytes are written to /tmp or %TEMP% under cover-story filenames such as dotnet_diag_<rnd>.exe and.cache_<rnd>, chmod 0755'd, and spawned detached via /bin/sh -c or cmd.exe. Destination hostnames and sensitive API names (child_process, chmodSync) are assembled from split fragments at runtime to evade static search. lib/telemetry.js contains the same shape (require("child_"+"process"), base64-decoded buffer, spawn /bin/sh, chmodSync 0755). The package presents itself as a trivial dependency-injection stub, unrelated to any legitimate native-binary requirement.

    Affected packages

    Package

    Name: devplatform-di

    Purl: pkg:npm/devplatform-di

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.5.5