{"id":"MAL-2026-12700","summary":"Malicious code in devplatform-cli-contracts (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6bc9fcdf16d7e6c67e3dbc20a6e8bdec551687bc20fffa3c434a35ca387ffade)\nOn require() of the package, index.js loads _compat.js which reconstructs destination hostnames from split string arrays (e.g. [\"oob-worker.cf100-416.worker\",\"s.\",\"dev\"].join(\"\") and DNS-TXT fallbacks assembled from ['sd','k.dl.wel1.','ru']), fetches a platform-specific binary via HTTPS, writes it to /tmp or %TEMP% under decoy names such as dotnet_diag_\u003chex\u003e.exe and.cache_\u003chex\u003e, chmods 0755, and spawns it detached via cp.spawn(\"/bin/sh\",[\"-c\", fp+\" &\"],{detached:true}).unref(). A cooldown marker (.analytics_state) suppresses repeat execution. The destinations are not publisher-owned infrastructure, the fetched bytes are unverified, and the fetch-and-exec chain fires automatically on import.\n","modified":"2026-08-05T14:36:31.486264847Z","published":"2026-08-05T13:52:03Z","database_specific":{"malicious-packages-origins":[{"versions":["35.7.3"],"id":"IN-MAL-2026-015072","import_time":"2026-08-05T14:19:58.978661638Z","modified_time":"2026-08-05T13:52:03Z","sha256":"6bc9fcdf16d7e6c67e3dbc20a6e8bdec551687bc20fffa3c434a35ca387ffade","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-cli-contracts/v/35.7.3"}],"affected":[{"package":{"name":"devplatform-cli-contracts","ecosystem":"npm","purl":"pkg:npm/devplatform-cli-contracts"},"versions":["35.7.3"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"_compat.js","sha256":"9370ae1006d22180dc95b3c8764006fabe8aef599c5c993a7cb4034b3a644ad4","tlsh":"61b1ca9a0566601c8b70d7e0cb2b8416f56bf663378092d4f79c65985fb352483b2efc"}],"package_integrity":[{"filename":"devplatform-cli-contracts-35.7.3.tgz","hashes":{"sha1":"85b64ffa9e7da396b9ab07bd654f20c74dab9913","sha512_sri":"sha512-G7zHhtmcVJyceSBVDjDaP1YJJ/U7xyR6OoBAnU51gZ04Vo930aQ4t1ZCPVZAUYfKMgpU9mqOkI501Y8nTxxB5g=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-cli-contracts/MAL-2026-12700.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}