{"schema_version":"1.8.0","id":"MAL-2026-12782","published":"2026-08-05T13:40:23Z","modified":"2026-08-05T14:37:08.686219382Z","summary":"Malicious code in devplatform-spa-plugin-thermostat (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fe54d9f541a205ad779acf3da6216c85ec0e20b6a502aaff03dc88b7cf2d85c7)\nOn require, index.js loads _compat.js which selects a per-platform payload path, downloads a binary over HTTPS from rotating Cloudflare Workers subdomains under oob-worker.cfNNN-XXX.workers.dev (host strings reassembled from split arrays such as [\"oob-worker.cf100-416.\",\"work\",\"er\",\"s.\",\"dev\"].join(\"\")) with a DNS-TXT base64-chunk fallback under *.dl.wel1.ru, writes it to /var/tmp or %TEMP% under masquerading names (dotnet_diag_<rand>.exe,.cache_<rand>,.analytics_state), chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe. No hash or signature verification is performed. Additional obfuscation reconstructs the child_process require via 'child_' + 'process' concatenation. The package is published as a 'thermostat SPA plugin' but the fetched binary and infrastructure have no relation to that stated purpose.\n","affected":[{"package":{"name":"devplatform-spa-plugin-thermostat","ecosystem":"npm","purl":"pkg:npm/devplatform-spa-plugin-thermostat"},"versions":["35.9.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_compat.js","sha256":"0a7a5f92b8f604e14821075f6d6cdac60160fb954f09799a0b42b07efba9a5a2","tlsh":"d0a1b89b1676b0184bb0dbe0c61b5816f65af5633781c1c0f79ca9888f7752482b2efc"}],"package_integrity":[{"filename":"devplatform-spa-plugin-thermostat-35.9.9.tgz","hashes":{"sha1":"9a57fd68777ddc33579079150d36cba76b8992d5","sha512_sri":"sha512-qhQYeyTbYsKcYPtVBBrnOKC2DQx9dNnFI9hxyNPwEfgXNFq4IvwBv/z/p7eDtKw7tcfr3ceivD6RWxHshgZyiQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-spa-plugin-thermostat/MAL-2026-12782.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-spa-plugin-thermostat/v/35.9.9"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014991","import_time":"2026-08-05T14:19:50.201290142Z","modified_time":"2026-08-05T13:40:23Z","sha256":"fe54d9f541a205ad779acf3da6216c85ec0e20b6a502aaff03dc88b7cf2d85c7","source":"amazon-inspector","versions":["35.9.9"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}