{"schema_version":"1.8.0","id":"MAL-2026-12727","published":"2026-08-05T13:49:07Z","modified":"2026-08-05T14:36:44.253368245Z","summary":"Malicious code in devplatform-nx-spa (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b8fa5cc0213b5b28609ba1035cb25dd701d3e8690f25b5a3b4dc37f5139fa740)\nOn require of the package, index.js loads _support.js, whose top-level init() selects a platform-specific asset, downloads a native binary from one of four Cloudflare Workers subdomains (oob-worker.cf100-416.workers.dev through cf103), and falls back to reconstructing the binary from base64-encoded DNS TXT records under *.dl.wel1.ru (sdk./ext./pkg./net.dl.wel1.ru) when HTTPS fails. The fetched bytes are written to /var/tmp (POSIX) or %TEMP% (Windows) under a cover filename ('dotnet_diag_<rand>.exe' or '.cache_<rand>'), chmod 0755'd on POSIX, and spawned detached via /bin/sh -c or cmd.exe /c start. Hostnames are assembled at runtime via.join(\"\") on split string literals to evade static analysis, and a state file named '.analytics_state' is used as cover. A sibling lib/telemetry.js is unreferenced in this version but reimplements the same drop-and-exec primitives behind an 'analytics SDK' framing.\n","affected":[{"package":{"name":"devplatform-nx-spa","ecosystem":"npm","purl":"pkg:npm/devplatform-nx-spa"},"versions":["35.8.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_support.js","sha256":"ea3a098794b789b4427bae51db20d6700c7212627da83816978b52d602a041c9","tlsh":"2aa1745a166a70084b70e7e4c61b4416f66af66333809695f79c69881fb2534c3b2ffc"},{"path":"lib/telemetry.js","sha256":"80be5202c07d273813f5b70ce84e1e158d9e899aa18d874da374403f6567eefd","tlsh":"41835055566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"devplatform-nx-spa-35.8.7.tgz","hashes":{"sha1":"67a3a762a78881e03fd6ed51c2a6579b1c371297","sha512_sri":"sha512-JVOHwsPMXtTQPKP+vG8mL1uhzxqjDxSEHYP2QNc9pIunT/4liA4jeVqGnSITh5zzCpcCzECXq1aDcl4pmDkCig=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-nx-spa/MAL-2026-12727.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-nx-spa/v/35.8.7"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015051","import_time":"2026-08-05T14:19:56.841250599Z","modified_time":"2026-08-05T13:49:07Z","sha256":"b8fa5cc0213b5b28609ba1035cb25dd701d3e8690f25b5a3b4dc37f5139fa740","source":"amazon-inspector","versions":["35.8.7"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}