{"id":"MAL-2026-13263","summary":"Malicious code in devplatform-spa-use-track (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (59ba2c5091a95bcff203618393da399071dba1859bb0af79ca39021b7a1bdb5f)\nOn require() of the package, index.js loads _polyfill.js which fetches a platform-specific binary from one of four Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev) with DNS TXT fallback to sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru. Hostnames are assembled at runtime from split string fragments and child_process is loaded via require(\"child_\"+\"process\") to evade static substring scanning. The downloaded binary is written to /tmp or the Windows Temp directory under a disguised name (.cache_\u003chex\u003e on Linux, dotnet_diag_\u003chex\u003e.exe on Windows), chmod 0755 is applied through a computed \"chmod\"+\"Sync\" property lookup, and the file is spawned detached via /bin/sh -c or cmd.exe /c start /b. The package's advertised purpose is a trivial SPA tracking helper, which does not require any of this behavior. A second file, lib/telemetry.js (~81 KB, styled as a Sentry-like analytics SDK), contains an independent copy of the same fetch/chmod/spawn dropper primitives and ships as an alternate payload path in the tarball. The destination hosts are attacker-controlled, publisher-mismatched, and mutable; the executed bytes are opaque and unverified.\n","modified":"2026-08-05T16:50:23.359840858Z","published":"2026-08-05T15:31:29Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.5.3"],"id":"IN-MAL-2026-015732","import_time":"2026-08-05T16:13:37.443289381Z","modified_time":"2026-08-05T15:31:29Z","sha256":"59ba2c5091a95bcff203618393da399071dba1859bb0af79ca39021b7a1bdb5f"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-spa-use-track/v/35.5.3"}],"affected":[{"package":{"name":"devplatform-spa-use-track","ecosystem":"npm","purl":"pkg:npm/devplatform-spa-use-track"},"versions":["35.5.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-spa-use-track/MAL-2026-13263.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"devplatform-spa-use-track-35.5.3.tgz","hashes":{"sha1":"f2d2b83acc27933ba0def993fd936888b7e2b940","sha512_sri":"sha512-x1ZTtiPiK/iPCoseO/tO9auZ2scnMpbnMWyRorNZZlmDfPh0ak2BLCm8+CLf4cjnienHNA49kdPv656xEf9v9w=="}}],"evidence_files":[{"tlsh":"27a1879a126670184bb0d7e4c71b8826f66bf6633680c6c4f79c65945fb352483b2efc","path":"_polyfill.js","sha256":"3b6e4f6258ce04214289c2982163b728a3c4586b2afd8c6a0de0f9ec706332da"},{"sha256":"e44d9ada15db2055ca512890e5d434c3922e42ad47922f1f0cb4f9136bdb82ac","tlsh":"fb835055566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}