{"id":"MAL-2026-13270","summary":"Malicious code in devplatform-ui-notification (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (74230ed898152bc75d702938fcac9bd53e13ff7100120b44c5944bb8226225f7)\nindex.js unconditionally requires./_compat on load, which selects a platform-specific asset path (linux/darwin/win32) and downloads bytes over HTTPS from string-obfuscated Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev) with a DNS-TXT base64 fallback channel under *.dl.wel1.ru. The downloaded payload is written to /var/tmp (or the Windows TEMP directory) under a disguised name resembling dotnet_diag_*.exe /.cache_*, chmodded to 0755, and spawned detached via /bin/sh -c '\u003cfile\u003e &' or cmd /c start with stdio ignored. Destination hosts are assembled from split string fragments (e.g. [\"oob-worker.cf\",\"103-070\",\".worker\",\"s.\",\"de\",\"v\"].join(\"\")) and child_process / chmodSync are required via string concatenation (require(\"child_\" + \"process\"), fs[\"chmod\" + \"Sync\"]) to evade static URL and API scanning. The same download-then-execute chain is duplicated in lib/telemetry.js (81KB). There is no version pinning, no hash or signature verification, and the destinations are unrelated to a UI notification library.\n","modified":"2026-08-05T16:50:26.301579356Z","published":"2026-08-05T15:29:33Z","database_specific":{"malicious-packages-origins":[{"sha256":"74230ed898152bc75d702938fcac9bd53e13ff7100120b44c5944bb8226225f7","source":"amazon-inspector","versions":["35.3.6"],"id":"IN-MAL-2026-015719","import_time":"2026-08-05T16:13:35.870731798Z","modified_time":"2026-08-05T15:29:33Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-ui-notification/v/35.3.6"}],"affected":[{"package":{"name":"devplatform-ui-notification","ecosystem":"npm","purl":"pkg:npm/devplatform-ui-notification"},"versions":["35.3.6"],"database_specific":{"indicators":{"package_integrity":[{"filename":"devplatform-ui-notification-35.3.6.tgz","hashes":{"sha1":"e92f4080ef33d8f07e9d53d314565bb7cb2e8bcd","sha512_sri":"sha512-vfZ/61mgB2P3Bmx3ugdTDGx+mUBXMpNoh46Piy6OUb8dD0P/m3I7RhV1W5/Slihox2XhDHOLB1OJN2N1w/eaeQ=="}}],"evidence_files":[{"path":"_compat.js","sha256":"fc643a35b2bc4ca51a27763a2ab119fbe34f76c3d9490be5b633e2e5afbbac33","tlsh":"3ea1826a1666711887b09be4c6175416f55bf26373809294fb9c69881ff312482b2efc"},{"path":"lib/telemetry.js","sha256":"adef07be70415f31552d0e492428697a508d9d149a24a63cb52c2a0ea3bb81e0","tlsh":"46835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-ui-notification/MAL-2026-13270.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}