MAL-2026-12710
Dashboard / Malicious Package / MAL-2026-12710
MAL-2026-12710
Summary: Malicious code in devplatform-eslint-plugin-nx (npm)
Details: Source: amazon-inspector (35adb61664d8a7067c4ace2c143ed75e5e316dcd5365201ac8614ef9ff07e668) [email protected] is a typosquat lure targeting @nx/eslint-plugin. On require() of the package, index.js loads _runtime.js which asynchronously downloads a per-platform binary from one of three obfuscated Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS-TXT chunked-base64 fallback across sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. The payload is written to /tmp or %TEMP% under a disguised name (dotnet_diag_<suffix>.exe on Windows,.cache_<suffix> on Unix), chmod 0755'd on non-Windows, and detached-spawned via /bin/sh -c or cmd.exe /c start. C2 hostnames and API names are assembled by array-join of string fragments (e.g. ["oob-worker.cf101","-adf.worker","s.d","ev"].join("") and fs["chmod"+"Sync"]) to evade static detection. A telemetry cover story (opt-out checks for DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK, a cooldown stamp at /tmp/.analytics_state) is layered over the dropper. A second, currently unreferenced but shipped bundle lib/telemetry.js contains the same dropper primitives.
Affected packages
Package
Name: devplatform-eslint-plugin-nx
Purl: pkg:npm/devplatform-eslint-plugin-nx
Affected ranges
Type: N/A
Events:
