{"id":"MAL-2026-12692","summary":"Malicious code in devplatform-api-endpoint (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4a79a64efe72b14455f83f667581664c2369f92f669983a58cede299f70bcadc)\nOn require() of the package's main entry, index.js unconditionally loads _bootstrap.js, which fetches a platform-specific binary from Cloudflare Workers hosts whose names are constructed by concatenating fragmented string literals (oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev). The downloaded bytes are written to a temp path with a masquerading filename (dotnet_diag_*.exe,.cache_*), chmod 0755'd, and spawned detached via child_process (/bin/sh -c or cmd.exe /c start). A DNS-TXT covert-channel fallback resolves TXT records under *.dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru) enumerated as c.\u003cdomain\u003e, 0.\u003cdomain\u003e, 1.\u003cdomain\u003e,... and base64-decodes the concatenated TXT payloads into an executable that is then written and run. Endpoint literals are fragmented (e.g., [\"oob-worker.cf101-\",\"ad\",\"f.workers.d\",\"ev\"].join(\"\")) purely to evade static matching. The package advertises no purpose that justifies fetching and executing remote binaries.\n","modified":"2026-08-05T14:36:27.773400638Z","published":"2026-08-05T13:53:33Z","database_specific":{"malicious-packages-origins":[{"sha256":"4a79a64efe72b14455f83f667581664c2369f92f669983a58cede299f70bcadc","source":"amazon-inspector","versions":["35.2.9"],"id":"IN-MAL-2026-015082","import_time":"2026-08-05T14:19:59.966219192Z","modified_time":"2026-08-05T13:53:33Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-api-endpoint/v/35.2.9"}],"affected":[{"package":{"name":"devplatform-api-endpoint","ecosystem":"npm","purl":"pkg:npm/devplatform-api-endpoint"},"versions":["35.2.9"],"database_specific":{"indicators":{"package_integrity":[{"filename":"devplatform-api-endpoint-35.2.9.tgz","hashes":{"sha512_sri":"sha512-JawWRfAOt1Q0bKtjd1E6ZrYTEKihntH52HSDEgcYR19ASUeeFJT+fNcHH4vZK16mtTFBVzMHrLMCpSa5XhAJNg==","sha1":"a7a2d33d5a13f9f12e6f91d2768fbe51c0e0434a"}}],"evidence_files":[{"tlsh":"38b1a85a166b701d4bb0dbe4c6174415f66ae6933380c688fb5c69880f77128c3b2efc","path":"_bootstrap.js","sha256":"532c78d06e6639458d491fa8b3b509c78608cd904e895ea81a776adfae0512eb"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-api-endpoint/MAL-2026-12692.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}