MAL-2026-12762

    Dashboard / Malicious Package / MAL-2026-12762

    MAL-2026-12762

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in devplatform-spa-plugin-beaver (npm)

    Details: Source: amazon-inspector (c4a35163a32dc9e4e60b1e9b09f33362ac19ea6e1486dfb4141a98a5263d1fa6) On require(), the package's _init.js selects a platform-specific URL from a set of Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev) whose hostnames are assembled from split-string fragments to evade static grep, downloads an opaque binary payload with no hash or signature verification, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows using filenames disguised as system diagnostics, chmods 0o755, and detach-spawns it via /bin/sh -c or cmd /c start with unref() so the child outlives the require. A DNS-TXT covert channel over subdomains of sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru provides a fallback transport that reassembles base64 chunks from numbered TXT records, bypassing HTTP egress filtering. Execution is gated by cover-story opt-outs (DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK) and a ~6h TTL marker at /tmp/.analytics_state or %TEMP%\analytics_state so the dropper fires once per fresh host to reduce detection surface. The fetched bytes have no relation to the advertised 'spa plugin' function, and the fetch destinations are neither the npm registry nor a publisher-matched vendor host.

    Affected packages

    Package

    Name: devplatform-spa-plugin-beaver

    Purl: pkg:npm/devplatform-spa-plugin-beaver

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.2.2
    MAL-2026-12762 | CVE-DB