{"id":"MAL-2026-12752","summary":"Malicious code in devplatform-select-user (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e2f7e22a3a99d2447b8bc3e6c0b1f4a92077ce570fdacff421e9fdee6a83e723)\nOn require(), the package loads _bridge.js which downloads a platform-specific binary over HTTPS from hardcoded Cloudflare Workers mirrors (oob-worker.cf99-9b3.workers.dev, cf101-adf.workers.dev, cf102-baf.workers.dev), writes it to /var/tmp or %TEMP% under cover-story names such as.cache_\u003chex\u003e and dotnet_diag_\u003chex\u003e.exe, chmods it 0755, and spawns it detached via cp.spawn('/bin/sh', ['-c', fp+' &']) on POSIX or cmd on Windows. Destination hostnames are reconstructed at runtime from split character arrays (['oob-worker.cf99-9b3.worke','rs.','de','v'].join('')) to evade string-based scanners. A DNS fallback channel resolves TXT records under *.dl.wel1.ru (assembled the same way in _DNS_MAP) to retrieve or exfiltrate chunked data when HTTPS is blocked. The package's advertised purpose is a 'select user' UI helper — there is no functional reason for it to fetch and execute an opaque native binary from anonymous Cloudflare Workers subdomains at import time. Cover-story comments ('Shuffle endpoints to distribute load', 'Clean up temporary files') and a DISABLE_TELEMETRY opt-out gate frame the dropper as diagnostics. Installing or importing this package results in attacker-controlled code executing on the host.\n","modified":"2026-08-05T14:36:55.344096882Z","published":"2026-08-05T13:45:19Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T13:45:19Z","sha256":"e2f7e22a3a99d2447b8bc3e6c0b1f4a92077ce570fdacff421e9fdee6a83e723","source":"amazon-inspector","versions":["35.4.4"],"id":"IN-MAL-2026-015026","import_time":"2026-08-05T14:19:53.964580372Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-select-user/v/35.4.4"}],"affected":[{"package":{"name":"devplatform-select-user","ecosystem":"npm","purl":"pkg:npm/devplatform-select-user"},"versions":["35.4.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-select-user/MAL-2026-12752.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"_bridge.js","sha256":"5f6a1ab3764bae37a268fba82cea60313f1e19f1e9e70fb7062206542b2d4d1f","tlsh":"42a1845a05a670084bb0d7f4c717541af65bf26333808298f6ac65985fb252483f2efc"}],"package_integrity":[{"filename":"devplatform-select-user-35.4.4.tgz","hashes":{"sha1":"2ae4804fa3c8e5def4d7635405212e4a537f305c","sha512_sri":"sha512-TAw4lF4Cng5CTHG/nSRL9vnO+BL/o3/eU9tlrOj1CR3INYdjCPbTwVYciEP/7jbIvyAZIb6nk27Esc4VLvLVpw=="}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}