{"schema_version":"1.8.0","id":"MAL-2026-12717","published":"2026-08-05T13:49:40Z","modified":"2026-08-05T14:36:39.539145707Z","summary":"Malicious code in devplatform-jscodeshift-plugin (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (92dcd946aaaf9b57795f9a94877df34a69ac39828620c58e2cf4b72cd7a9c253)\nOn require(), index.js loads _loader.js, which reconstructs Cloudflare Workers hostnames from split string fragments (e.g. ['oob-worke','r.cf101-a','df.workers.d','ev'].join('')) and a DNS-TXT fallback channel via fragmented 'sdk.dl.wel1.ru' resolvers, downloads a platform-specific binary, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%\\dotnet_diag_<hex>.exe on Windows, chmods it 0o755, and spawns it detached via cp.spawn('/bin/sh',['-c', fp+' &']) or spawn('cmd',...). The dropped artifacts use names impersonating telemetry / dotnet diagnostics, and environment variables like DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK are honored to provide a cover story. The package has no jscodeshift-plugin functionality and appears to be a name-squat lure whose only purpose is dropping and executing this remote payload.\n","affected":[{"package":{"name":"devplatform-jscodeshift-plugin","ecosystem":"npm","purl":"pkg:npm/devplatform-jscodeshift-plugin"},"versions":["35.4.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_loader.js","sha256":"e01b9d9bab23ea52b831539486f52e7bdb6734093251b52d047b0dca3c9797d5","tlsh":"b6a1b95a05a6300c4bb09bf5c71b441af65be6533380c294fb5c69986f7352483b2dfc"}],"package_integrity":[{"filename":"devplatform-jscodeshift-plugin-35.4.1.tgz","hashes":{"sha1":"2ddac8039df3dde7598ca1b5d926f1e15955b2cc","sha512_sri":"sha512-9ZOEQnj0RupTMlBsNY879RqCWzBMAn9v+rhAuAdJ8RTgfvDX4Mtpom2N4lps7t4TQabRVE5Hkh78GwvI26c7NQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-jscodeshift-plugin/MAL-2026-12717.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-jscodeshift-plugin/v/35.4.1"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015055","import_time":"2026-08-05T14:19:57.210548194Z","modified_time":"2026-08-05T13:49:40Z","sha256":"92dcd946aaaf9b57795f9a94877df34a69ac39828620c58e2cf4b72cd7a9c253","source":"amazon-inspector","versions":["35.4.1"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}