{"id":"MAL-2026-13544","summary":"Malicious code in devplatform-eslint-config (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (de0fcdb30a4308ee477f432e1bcc665e8ee45f3dd36dd02f22089a4b9e2a69f9)\ndevplatform-eslint-config@35.8.9 ships no ESLint configuration despite its name and description. Requiring the package loads _compat.js, which on import selects a payload path based on OS/architecture (linux_x64, linux_arm64, darwin, win32), fetches an opaque native binary over HTTPS from a rotating set of Cloudflare Workers hosts whose names are assembled at runtime by joining split string fragments (oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev), with a DNS-TXT covert-channel fallback that reassembles base64 chunks from TXT records under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The fetched bytes are written to a temporary path with a decoy filename (e.g. dotnet_diag_*.exe,.cache_*), chmod 0755, and executed via a detached child process (cp.spawn('/bin/sh',['-c', fp+' &'], {detached:true}) on POSIX, cmd.exe start /b on Windows). lib/telemetry.js contains duplicate fetch-write-chmod-spawn primitives. Runtime string assembly of C2 hostnames hides destinations from static analysis, and the ESLint-config identity is a cover story unrelated to the shipped code.\n","modified":"2026-08-07T13:20:24.256200501Z","published":"2026-08-07T12:25:53Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.8.9"],"id":"IN-MAL-2026-016977","import_time":"2026-08-07T12:51:20.612862599Z","modified_time":"2026-08-07T12:25:53Z","sha256":"de0fcdb30a4308ee477f432e1bcc665e8ee45f3dd36dd02f22089a4b9e2a69f9"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-eslint-config/v/35.8.9"}],"affected":[{"package":{"name":"devplatform-eslint-config","ecosystem":"npm","purl":"pkg:npm/devplatform-eslint-config"},"versions":["35.8.9"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"1ba1955a156670088bb0dbe4c7175416f6abf6632780c298fb6ca5884fb356883b1dfc","path":"_compat.js","sha256":"ade3278944e896438532b00f202ac4ff11cfda4c4c050a45e698e4d9840cec94"},{"tlsh":"b3c02223c120ac2301b01d41dce119273ba21f1f10229c0eb673321c02e457100de312","path":"package.json","sha256":"70413de21a15d2f160031a45559fcab67a72a1c18051d5bd8488f4a89328ecee"}],"package_integrity":[{"filename":"devplatform-eslint-config-35.8.9.tgz","hashes":{"sha512_sri":"sha512-N3IsQYzwLm4iDrfO8WGGSEnrsuzN+nDBndiNXNOFxOzlbAC8tOaQk8F4/QW8shIwOLV0xTaCfKi+eAu4amCBNg==","sha1":"58c61da62d23635c70d38c1ea2572b1e58ec5ad1"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-eslint-config/MAL-2026-13544.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}