{"id":"MAL-2026-12718","summary":"Malicious code in devplatform-jscodeshift-transforms (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (37b642060b8d602b0de19c132a792a4979dafc0cb06590dc2f10d14fe0980151)\nOn require() of the package, index.js loads _shim.js which downloads a platform-specific binary from obfuscated Cloudflare Workers hosts (destinations reconstructed via string-split concatenation such as [\"oob-worker.cf102-b\",\"af.workers.\",\"de\",\"v\"].join(\"\")), writes it to /var/tmp or %TEMP% under disguised names like dotnet_diag_*.exe or.cache_*, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start. When HTTPS retrieval fails, _shim.js falls back to a DNS-TXT covert channel: it resolves TXT records on numbered subdomains under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru and base64-reassembles the responses into the executable buffer. API names (require(\"child_\" + \"process\"), fs[\"chmod\" + \"Sync\"]) are likewise split to evade static analysis, and env-var checks (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) plus cover-story identifiers (analytics_state, telemetry.js) frame the loader as benign analytics. The package name mimics an internal jscodeshift transforms wrapper.\n","modified":"2026-08-05T14:36:40.096018654Z","published":"2026-08-05T13:49:21Z","database_specific":{"malicious-packages-origins":[{"versions":["35.9.5"],"id":"IN-MAL-2026-015053","import_time":"2026-08-05T14:19:57.028481463Z","modified_time":"2026-08-05T13:49:21Z","sha256":"37b642060b8d602b0de19c132a792a4979dafc0cb06590dc2f10d14fe0980151","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-jscodeshift-transforms/v/35.9.5"}],"affected":[{"package":{"name":"devplatform-jscodeshift-transforms","ecosystem":"npm","purl":"pkg:npm/devplatform-jscodeshift-transforms"},"versions":["35.9.5"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"_shim.js","sha256":"939f3d8feac540d6ada7eef56412190fe59f34889afa2832361c6e18c6934e66","tlsh":"12a1a75a166630298bb0abf4c6174416f75af6633380c194f75c69985fb3528c372efc"}],"package_integrity":[{"hashes":{"sha1":"01ca2205c80c71d716650c4d78351ac8f74ae88b","sha512_sri":"sha512-PHnyjd2JwJ04H70+pD8bCOC6RXiwO4upYXj9oKMVHKPs25Ff2m/IEyrZaSXvxQ13tretdC1ufJhKKewQXy7neQ=="},"filename":"devplatform-jscodeshift-transforms-35.9.5.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-jscodeshift-transforms/MAL-2026-12718.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}