MAL-2026-12722
Dashboard / Malicious Package / MAL-2026-12722
MAL-2026-12722
Summary: Malicious code in devplatform-nx-devkit (npm)
Details: Source: amazon-inspector (cc4017373371f50665290c944ee840b2ad4a7e745dcb5eb973f977185b150ac7) The package presents as a devkit for the Nx ecosystem but ships a trivial no-op class in index.js alongside a hidden _shim.js. On require, index.js unconditionally invokes require('./_shim'), which reconstructs destination hostnames via array-join over split fragments (assembling oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, with a DNS TXT fallback channel through sdk/ext/pkg/net.dl.wel1.ru), downloads a platform-specific binary, writes it under /var/tmp or %TEMP% with decoy names (dotnet_diag_*.exe,.analytics_state,.cache_*), chmods 0755, and detached-spawns it via /bin/sh -c or cmd. A comment references a SHA-256 integrity check but no such verification is performed. Opt-out environment variables (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) and a sibling lib/telemetry.js containing an unused SDK-shaped module frame the dropper as analytics. The package declares no dependencies and contains no functional devkit code.
Affected packages
Package
Name: devplatform-nx-devkit
Purl: pkg:npm/devplatform-nx-devkit
Affected ranges
Type: N/A
Events:
