{"id":"MAL-2026-12707","summary":"Malicious code in devplatform-create-nx-spa (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6060fc08151209041eab336a6dcfdff0e78efb3a5d5dc7834df7e4f61ac03464)\ndevplatform-create-nx-spa@35.4.9 ships an `index.js` main entry that silently `require()`s `_bridge.js`, which on load assembles Cloudflare Workers hostnames (`oob-worker.cf10{0,1,2,3}-*.workers.dev`) and a fallback DNS-TXT channel to `*.dl.wel1.ru` from split-string arrays joined at runtime, downloads an unsigned opaque binary, writes it to `/var/tmp/.cache_\u003chex\u003e` on Unix or `%TEMP%\\dotnet_diag_\u003chex\u003e.exe` on Windows, `chmod 0755`s it, and spawns it detached via `spawn('/bin/sh', ['-c', \u003cpath\u003e+' &'], {detached:true})` or `spawn('cmd',...)`. The behavior is disguised as \"analytics\" and gated by an `/tmp/.analytics_state` timestamp. The `child_process` identifier and destination hostnames are assembled from 3-4 substring pieces (`['oob-worker.cf103-070.wor','ke','rs.dev'].join('')`, `require('child_'+'process')`) to defeat static string matching. The package presents itself as a lightweight Nx SPA scaffolder, but its main module's only load-time effect is to fetch and execute attacker-controlled code on the installer's host.\n","modified":"2026-08-05T14:36:34.928623412Z","published":"2026-08-05T13:51:55Z","database_specific":{"malicious-packages-origins":[{"sha256":"6060fc08151209041eab336a6dcfdff0e78efb3a5d5dc7834df7e4f61ac03464","source":"amazon-inspector","versions":["35.4.9"],"id":"IN-MAL-2026-015071","import_time":"2026-08-05T14:19:58.878424752Z","modified_time":"2026-08-05T13:51:55Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-create-nx-spa/v/35.4.9"}],"affected":[{"package":{"name":"devplatform-create-nx-spa","ecosystem":"npm","purl":"pkg:npm/devplatform-create-nx-spa"},"versions":["35.4.9"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"devplatform-create-nx-spa-35.4.9.tgz","hashes":{"sha1":"a133614540ab57effae3ae9eef5fbb04e9b0e401","sha512_sri":"sha512-UCK24J8Th5TLTFxAj5YN8A+m82pZ2CCBesClBfQoLkTpbTAmk+Kc0J0PTWaJJxN3ggNmerdi8W4HZeBdujbA6A=="}}],"evidence_files":[{"path":"_bridge.js","sha256":"ce8470e3516445061ee0745c3f118c14c260c9eb3a278f1d4d24aacee8aee842","tlsh":"00a1c69a126670184bb0d7e4c71b8816f616f6a33781c2c8f79c55984fb342483b2efc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-create-nx-spa/MAL-2026-12707.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}