{"id":"MAL-2026-12696","summary":"Malicious code in devplatform-api-v2-resources (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (186e6a9062d157dd85fb6e2ec2fc4a81294569d2cca0c2ade69f2e97075616ed)\nOn require() of devplatform-api-v2-resources@35.3.8, index.js loads./_polyfill.js, which downloads a platform-specific binary from anonymous Cloudflare Workers subdomains (oob-worker.cf1*-*.workers.dev) with a DNS TXT fallback that reassembles a base64 payload from numbered TXT records under sdk/ext/pkg/net.dl.wel1.ru. Destination hostnames are constructed at runtime by joining split-string fragments (e.g. [\"oob-worker.cf101-adf.wor\",\"kers\",\".de\",\"v\"].join(\"\")) to evade static analysis. The fetched bytes are written to /tmp/.cache_\u003chex\u003e or %TEMP%\\dotnet_diag_\u003chex\u003e.exe with disguised names, chmod 0755, and spawned detached via cp.spawn(\"/bin/sh\",[\"-c\", fp+\" &\"], {detached:true}).unref() (or spawn(\"cmd\",...) on Windows). A cache stamp suppresses re-download within a TTL. A dormant secondary copy of the same dropper family (write+chmod+spawn styled as an APM SDK) is present in lib/telemetry.js but is not reached from the current loader graph. The fetched payload is unpinned, unverified, opaque, and from author-controlled anonymous infrastructure whose identifiers are hidden by string-split obfuscation.\n","modified":"2026-08-05T14:36:30.265640941Z","published":"2026-08-05T13:52:41Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015076","import_time":"2026-08-05T14:19:59.404760266Z","modified_time":"2026-08-05T13:52:41Z","sha256":"186e6a9062d157dd85fb6e2ec2fc4a81294569d2cca0c2ade69f2e97075616ed","source":"amazon-inspector","versions":["35.3.8"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-api-v2-resources/v/35.3.8"}],"affected":[{"package":{"name":"devplatform-api-v2-resources","ecosystem":"npm","purl":"pkg:npm/devplatform-api-v2-resources"},"versions":["35.3.8"],"database_specific":{"indicators":{"package_integrity":[{"filename":"devplatform-api-v2-resources-35.3.8.tgz","hashes":{"sha1":"816988156c49f4db548af40feb7b1ed3a1584323","sha512_sri":"sha512-/I8ptsk2T0q5yjfs9m1rqcZ+SNGx1tKICHbAodBlUQr8VOQZGfZ8rfwZDy/pXjRqHUPalAhZPGbK9SiPnZwedw=="}}],"evidence_files":[{"sha256":"ed87482444ff465a221bad8f1ce28f50cedf56e0df3ead209eb38c69f99a9346","tlsh":"2ea1b996126670184bb0a7e4c72b5416f65be66337c0c294f79ca5981fb7128c372efc","path":"_polyfill.js"},{"sha256":"bc2e0d309344cba57d67cd8f90da0c4470c1fb5ac357d4b1cf5371c8c06eb00a","tlsh":"19835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-api-v2-resources/MAL-2026-12696.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}