{"id":"MAL-2026-12722","summary":"Malicious code in devplatform-nx-devkit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cc4017373371f50665290c944ee840b2ad4a7e745dcb5eb973f977185b150ac7)\nThe package presents as a devkit for the Nx ecosystem but ships a trivial no-op class in index.js alongside a hidden _shim.js. On require, index.js unconditionally invokes require('./_shim'), which reconstructs destination hostnames via array-join over split fragments (assembling oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, with a DNS TXT fallback channel through sdk/ext/pkg/net.dl.wel1.ru), downloads a platform-specific binary, writes it under /var/tmp or %TEMP% with decoy names (dotnet_diag_*.exe,.analytics_state,.cache_*), chmods 0755, and detached-spawns it via /bin/sh -c or cmd. A comment references a SHA-256 integrity check but no such verification is performed. Opt-out environment variables (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) and a sibling lib/telemetry.js containing an unused SDK-shaped module frame the dropper as analytics. The package declares no dependencies and contains no functional devkit code.\n","modified":"2026-08-05T14:36:41.548097504Z","published":"2026-08-05T13:48:49Z","database_specific":{"malicious-packages-origins":[{"sha256":"cc4017373371f50665290c944ee840b2ad4a7e745dcb5eb973f977185b150ac7","source":"amazon-inspector","versions":["35.8.5"],"id":"IN-MAL-2026-015049","import_time":"2026-08-05T14:19:56.560780732Z","modified_time":"2026-08-05T13:48:49Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-nx-devkit/v/35.8.5"}],"affected":[{"package":{"name":"devplatform-nx-devkit","ecosystem":"npm","purl":"pkg:npm/devplatform-nx-devkit"},"versions":["35.8.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-nx-devkit/MAL-2026-12722.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"devplatform-nx-devkit-35.8.5.tgz","hashes":{"sha1":"1bebed3bc07abf0dc082772e3f91f3c2ab22fd82","sha512_sri":"sha512-7D7Epf7st+ywFla7OIn7inV6jCaj5ulqDcMInJQgyNLS8eWe/Gr+HCVQjhh86crpqFd4cw0GdXncq2OjZb3AOA=="}}],"evidence_files":[{"path":"_shim.js","sha256":"a03e72c36c77203b0e06f815143e47ef99d55ea8ccc7fda7914a4ce67bf12ed8","tlsh":"56b1869a16aa70198bb0dbf487175426f55af6633380c184fb5ca5885f7712483b1dfc"},{"path":"index.js","sha256":"50566421a228acf2b8d3c3e1161edae0960c9cb66309f256d509af0dc181edc7","tlsh":"bcf0fc9716daec72877463a3daf21051f5a284315f47415c759850de0ba0c5002adfba"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}