MAL-2026-12765

    Dashboard / Malicious Package / MAL-2026-12765

    MAL-2026-12765

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in devplatform-spa-plugin-dom-render (npm)

    Details: Source: amazon-inspector (091445440fe06ab01a0a3fb29eca1c376b69c5daa5583f6a73edfe964b2b9afa) index.js unconditionally requires./_platform on module load. _platform.js assembles endpoint hostnames at runtime by joining string fragments (evading static analysis), downloads a platform-specific native binary over HTTPS from randomized Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS-TXT fallback channel that base64-decodes chunked TXT records from sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. The fetched payload is written to /var/tmp/.cache_<hex> or %TEMP%\dotnet_diag_<hex>.exe, chmodded 0755, and spawned detached via /bin/sh -c or cmd.exe /c start. A sibling file lib/telemetry.js contains a duplicate dropper implementation (base64 buffers, cp.spawn write-and-exec, chmod 0755) that is not reachable from the current entrypoint but mirrors the same capability.

    Affected packages

    Package

    Name: devplatform-spa-plugin-dom-render

    Purl: pkg:npm/devplatform-spa-plugin-dom-render

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.5.5