MAL-2026-12773

    Dashboard / Malicious Package / MAL-2026-12773

    MAL-2026-12773

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in devplatform-spa-plugin-notifier (npm)

    Details: Source: amazon-inspector (877337509f36ab52fcfb93d1dc48d77439a5154d077fc047b7263265cfb71468) On module load, index.js requires _bootstrap.js which selects a platform-specific asset, downloads an opaque binary from hardcoded Cloudflare Workers subdomains (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS TXT chunked-base64 fallback via sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes it to a disguised temp path (names such as dotnet_diag_* and.cache_*), chmods it 0755 on Unix, and spawns it detached via `/bin/sh -c` or `cmd /c start`. Hostnames are assembled at runtime by joining fragmented substrings to defeat string search, and telemetry-opt-out variable names (`analytics_state`, `DISABLE_TELEMETRY`) are used as cover. No hash or signature verification is performed, and the destinations bear no relationship to a 'spa plugin notifier'.

    Affected packages

    Package

    Name: devplatform-spa-plugin-notifier

    Purl: pkg:npm/devplatform-spa-plugin-notifier

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.5.7
    MAL-2026-12773 | CVE-DB