MAL-2026-13543

    Dashboard / Malicious Package / MAL-2026-13543

    MAL-2026-13543

    Published: 7 Aug 2026Last Modified: 7 Aug 2026

    Summary: Malicious code in devplatform-api-v1-resources (npm)

    Details: Source: amazon-inspector (58312f0f83e88c3dbd6f62bc334db255d0e3d5c6aed0d8d859dd0b17ce77557c) On require of the package's main entry, setup.js fetches a platform-specific binary from Cloudflare Workers hosts whose names are reassembled at runtime from fragment arrays (e.g. oob-worker.cf101-*.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS TXT fallback under *.dl.wel1.ru. The fetched bytes are written to /var/tmp or the Windows TEMP directory under disguised names (dotnet_diag_<hex>.exe,.cache_<hex>), chmod'd to 0755, and spawned detached via /bin/sh on POSIX or cmd on Windows. No hash or signature verification is performed. A second copy of the same download-write-chmod-spawn pattern, using base64 chunk assembly and string-concatenated API names (fs["chmod"+"Sync"]), is shipped in lib/telemetry.js under the guise of a telemetry SDK. C2 hostnames are split into small fragments and joined at runtime to defeat static analysis, and endpoints rotate across multiple workers.dev subdomains with a.ru DNS fallback.

    Affected packages

    Package

    Name: devplatform-api-v1-resources

    Purl: pkg:npm/devplatform-api-v1-resources

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.4.7