MAL-2026-12741
Dashboard / Malicious Package / MAL-2026-12741
MAL-2026-12741
Summary: Malicious code in devplatform-react-scripts (npm)
Details: Source: amazon-inspector (b482d551faa8ecb3cb337bd8bacfe5ec193f1bc2cad69b3998e935fbaf413efa) The package's index.js requires./_init on load. _init.js reconstructs Cloudflare Workers hostnames via split-and-join obfuscation (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS-TXT base64 fallback under *.dl.wel1.ru, fetches a platform-specific binary over HTTPS, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd /c start. A.analytics_state marker file and env-var opt-out names (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) provide telemetry cover. The advertised 'react-scripts adapter' purpose does not match the dropped-and-executed opaque binary. Any consumer that installs and requires this package receives arbitrary attacker code execution on their machine.
Affected packages
Package
Name: devplatform-react-scripts
Purl: pkg:npm/devplatform-react-scripts
Affected ranges
Type: N/A
Events:
