{"id":"MAL-2026-13265","summary":"Malicious code in devplatform-supafetch (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8dc92f63aa9d199fde2a42c1298a9c620b5823b5252d16c9450456e5efbb154d)\ndevplatform-supafetch@35.2.1 is advertised as a fetch helper but on require() drops and executes an opaque native binary. index.js unconditionally loads./_ext.js, which selects a platform-specific payload path (/pkg/package, /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe), downloads it from one of four hardcoded Cloudflare Workers hosts (oob-worker.cf100-*.workers.dev through cf103-*.workers.dev), with a DNS-TXT fallback channel over subdomains of *.dl.wel1.ru that reassembles a base64-encoded payload from split TXT records. The downloaded bytes are written to /tmp/.cache_\u003crand\u003e or %TEMP%\\dotnet_diag_\u003crand\u003e.exe, chmod 0755, and launched detached via spawn(\"/bin/sh\", [\"-c\", fp+\" &\"]).unref() (or the cmd equivalent on Windows). Host names and DNS-fallback domain segments are constructed via [\"...\",\"...\"].join(\"\") to defeat static string matching. The behavior is disguised with cover-story labels (an 'analytics_state' flag file, 'dotnet_diag_*.exe' filename, gating on DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK env vars) that make the dropper appear to be optional telemetry. The dropped binary provides arbitrary remote code execution on the installer's host to the operator of the workers.dev / wel1.ru infrastructure.\n","modified":"2026-08-05T16:50:23.957452569Z","published":"2026-08-05T15:30:44Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T16:13:36.858702344Z","modified_time":"2026-08-05T15:30:44Z","sha256":"8dc92f63aa9d199fde2a42c1298a9c620b5823b5252d16c9450456e5efbb154d","source":"amazon-inspector","versions":["35.2.1"],"id":"IN-MAL-2026-015727"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-supafetch/v/35.2.1"}],"affected":[{"package":{"name":"devplatform-supafetch","ecosystem":"npm","purl":"pkg:npm/devplatform-supafetch"},"versions":["35.2.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"b6a1989a06a6b0198bb0d7e0c6178816f65bf563368192c4f79c95884fb35248372efc","path":"_ext.js","sha256":"cc126d2270cb391a3fb448e0c8209e492c3a5f525f68eec75049df3d104c3116"}],"package_integrity":[{"filename":"devplatform-supafetch-35.2.1.tgz","hashes":{"sha1":"8cb571bef95ba72c3d113865ad47ad50923ce1a6","sha512_sri":"sha512-/uvr4oEPjw9Xz+VmJPy69bdr3bhUNFRHlxtM3P1XVYC/oLChbJcMj6TCJ/Br7bP1SpK905AeFYk9oh62wWYjdg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-supafetch/MAL-2026-13265.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}