{"id":"MAL-2026-12757","summary":"Malicious code in devplatform-spa-di (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0b547ced93ce179bd009fd7e88e23e19ba63fdb224d9b32c62588f05a3fd40f5)\nOn require('devplatform-spa-di'), index.js loads _polyfill.js which fetches a platform-specific native binary from hardcoded Cloudflare Workers subdomains (oob-worker.cf100-416.workers.dev, cf99-9b3.workers.dev, cf101-adf.workers.dev, cf102-baf.workers.dev), with a DNS-TXT base64 fallback resolving through sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. The fetched bytes are written to /tmp/.cache_\u003crand\u003e on POSIX or %TEMP%\\dotnet_diag_\u003crand\u003e.exe on Windows, chmod 0755, and spawned detached via /bin/sh -c or cmd.exe /c start /b. Host strings and DNS domains are reconstructed at runtime by joining split array fragments (e.g. [\"oob-worker.cf100-416.worke\",\"rs.dev\"].join(\"\")) and cover-story comments frame the dropper as telemetry, with DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK env-var gates and an EXPIRE_SEC mtime stamp implementing dormancy and once-per-host gating. No hash or signature verification is performed. The package's advertised purpose is a small SPA dependency-injection helper, unrelated to native binary execution.\n","modified":"2026-08-05T14:36:57.031825714Z","published":"2026-08-05T13:43:22Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015013","import_time":"2026-08-05T14:19:52.632511413Z","modified_time":"2026-08-05T13:43:22Z","sha256":"0b547ced93ce179bd009fd7e88e23e19ba63fdb224d9b32c62588f05a3fd40f5","source":"amazon-inspector","versions":["35.5.8"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-spa-di/v/35.5.8"}],"affected":[{"package":{"name":"devplatform-spa-di","ecosystem":"npm","purl":"pkg:npm/devplatform-spa-di"},"versions":["35.5.8"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"5ba1846a12a670098770d7e4c6175416f65af6637780c294fb9ca9885ff312483f2efc","path":"_polyfill.js","sha256":"1e45502c735ddfcc0c0b7dee60a73e108c4fa262d0ba166f55c932ebe14f6f77"}],"package_integrity":[{"filename":"devplatform-spa-di-35.5.8.tgz","hashes":{"sha1":"356bf1a2b92f7c53c1d5857166012006eed9b1dd","sha512_sri":"sha512-bAXwoHdk8j68GcSW5v0levtNyGawCLBeQcKeedv4HkSW0u3A//qYP/rOBT9gDp16G0KW26FvpYCuj/dh9z5bmQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-spa-di/MAL-2026-12757.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}