{"id":"MAL-2026-12705","summary":"Malicious code in devplatform-confirm-input (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (68424c7a93599d9d6d9391e3236d1ebf1d88fdc590b9c20f1ee615295335e5e8)\ndevplatform-confirm-input@35.9.8 is advertised as a 'confirm input adapter' but on require() executes _ext.js, which fetches a platform-specific binary from string-concatenation-obfuscated Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), writes it to a temp path disguised as dotnet_diag_*.exe or a hidden.cache_* file, chmods it 0755, and spawns it detached via cmd.exe or /bin/sh. If HTTPS fails, a DNS-TXT chunked base64 fallback channel over sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru retrieves the payload. C2 hostnames and DNS-fallback domains are split into token arrays and reassembled at runtime, and the dropper uses cover-story identifiers ('.analytics_state', 'dotnet_diag_', 'Graceful degradation') to evade static analysis. Installing or importing this package results in remote code execution on the installer's host under attacker-controlled bytes.\n","modified":"2026-08-05T14:36:34.536994058Z","published":"2026-08-05T13:52:16Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:19:59.110437794Z","modified_time":"2026-08-05T13:52:16Z","sha256":"68424c7a93599d9d6d9391e3236d1ebf1d88fdc590b9c20f1ee615295335e5e8","source":"amazon-inspector","versions":["35.9.8"],"id":"IN-MAL-2026-015073"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-confirm-input/v/35.9.8"}],"affected":[{"package":{"name":"devplatform-confirm-input","ecosystem":"npm","purl":"pkg:npm/devplatform-confirm-input"},"versions":["35.9.8"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-confirm-input/MAL-2026-12705.json","indicators":{"evidence_files":[{"sha256":"284acc15ed7e164ba928b6be17a92c0a67ca45c38ac06c6c7c96bdb6e57bffd4","tlsh":"83b1a6aa116630198b70dba5c7179419f55af26367808294f79ca5885ff3224c3f2efc","path":"_ext.js"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-2vvaVLpczGDPdfvVgNyOPdKOAOtMUof4DfMfxQzOZ80nI6AXnvk7GAlNgGlyuezoZ7/ix04/xTUcx7O9xo28Bg==","sha1":"e23412e3a8c431b7c1c938803aa7006b661e54ac"},"filename":"devplatform-confirm-input-35.9.8.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}