{"id":"MAL-2026-12765","summary":"Malicious code in devplatform-spa-plugin-dom-render (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (091445440fe06ab01a0a3fb29eca1c376b69c5daa5583f6a73edfe964b2b9afa)\nindex.js unconditionally requires./_platform on module load. _platform.js assembles endpoint hostnames at runtime by joining string fragments (evading static analysis), downloads a platform-specific native binary over HTTPS from randomized Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS-TXT fallback channel that base64-decodes chunked TXT records from sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. The fetched payload is written to /var/tmp/.cache_\u003chex\u003e or %TEMP%\\dotnet_diag_\u003chex\u003e.exe, chmodded 0755, and spawned detached via /bin/sh -c or cmd.exe /c start. A sibling file lib/telemetry.js contains a duplicate dropper implementation (base64 buffers, cp.spawn write-and-exec, chmod 0755) that is not reachable from the current entrypoint but mirrors the same capability.\n","modified":"2026-08-05T14:37:00.545215174Z","published":"2026-08-05T13:42:18Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:19:51.79238162Z","modified_time":"2026-08-05T13:42:18Z","sha256":"091445440fe06ab01a0a3fb29eca1c376b69c5daa5583f6a73edfe964b2b9afa","source":"amazon-inspector","versions":["35.5.5"],"id":"IN-MAL-2026-015005"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-spa-plugin-dom-render/v/35.5.5"}],"affected":[{"package":{"name":"devplatform-spa-plugin-dom-render","ecosystem":"npm","purl":"pkg:npm/devplatform-spa-plugin-dom-render"},"versions":["35.5.5"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-PrpdtGghYstx3tVdZu6v8mSNru3W9BxDA5by/7IbwsuW0lox4xB+ZK3mVUhjM2UP1TiwOrRsAo9dNRO0ZK4DDA==","sha1":"3249a649c334f2ec98f5320b3aec66591873ca6a"},"filename":"devplatform-spa-plugin-dom-render-35.5.5.tgz"}],"evidence_files":[{"tlsh":"efa1969a16a670194fb0ebe4c61b8826f65ef6a333808184fb5c65985f7351483b1efc","path":"_platform.js","sha256":"11cbfabb965e70ceac1341bd98389537b865296f67f6c86c59cc1c19b32fd676"},{"path":"lib/telemetry.js","sha256":"81a442e154d7eb0c2be4ffe280cc797b8effeb5c5d0264be543eb19297285216","tlsh":"f7835056566a142186b2b368df234107ff3685272642429dbafc82dc1fbd72092a5ffc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-spa-plugin-dom-render/MAL-2026-12765.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}