{"id":"MAL-2026-12733","summary":"Malicious code in devplatform-po-transformer (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (555faac3cf4078b125af0858613813fb3f3bc780a573ddc5713b23d1046c9c71)\nOn require of the package, _platform.js detects OS/arch and downloads an opaque binary from Cloudflare Workers hostnames assembled at runtime from split-string arrays (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS-TXT covert-channel fallback under *.dl.wel1.ru that reassembles base64 chunks from N.\u003cdomain\u003e TXT records. The fetched bytes are written to /tmp/.cache_\u003crand\u003e on Unix or %TEMP%\\dotnet_diag_\u003crand\u003e.exe on Windows under deceptive filenames, chmod 0755, and spawned detached and unref'd via /bin/sh -c or cmd.exe /c start /b so the child survives the Node parent. There is no hash or signature verification; the download hosts are unrelated to the package publisher; a TTL marker at /tmp/.analytics_state suppresses re-execution within ~21000s. The fetch-decode-execute chain fires on import of the package's main entry, giving the operator of the remote endpoints arbitrary persistent code execution on the installer's host.\n","modified":"2026-08-05T14:36:46.999946971Z","published":"2026-08-05T13:47:18Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:19:55.38584091Z","modified_time":"2026-08-05T13:47:18Z","sha256":"555faac3cf4078b125af0858613813fb3f3bc780a573ddc5713b23d1046c9c71","source":"amazon-inspector","versions":["35.1.8"],"id":"IN-MAL-2026-015039"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-po-transformer/v/35.1.8"}],"affected":[{"package":{"name":"devplatform-po-transformer","ecosystem":"npm","purl":"pkg:npm/devplatform-po-transformer"},"versions":["35.1.8"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"4aa1969a16a970198bb0dbe486174816f65ff6633380c2d4fb6ca9885f731248371dfc","path":"_platform.js","sha256":"baea316d8a1e3a3cea2c01db8c8351666d2ca0098e7fc8fccccc30f65fcf0519"}],"package_integrity":[{"hashes":{"sha1":"7607fd7b6f6afe2b83d724de5954d451440db8f5","sha512_sri":"sha512-6O8tSPsjoJIXzjAkDaLAIJSxYftLrTdoHh9vsF6TIGL6XCrTc8DzZzN/FImUSqJd2+vF1vSIDcrVzq0+xoYPrQ=="},"filename":"devplatform-po-transformer-35.1.8.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-po-transformer/MAL-2026-12733.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}