{"schema_version":"1.8.0","id":"MAL-2026-13267","published":"2026-08-05T15:31:51Z","modified":"2026-08-05T16:50:25.046192018Z","summary":"Malicious code in devplatform-test-pvm-is-even (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4ab114c230ec1d462306a74f0eaaddf32474b1fae0087e1038ab2e280637d558)\nThe main entry index.js requires./_runtime.js, which at load time assembles hostnames from split string arrays (e.g. 'oob-worker.cf101-adf.workers.dev' and 'sdk.dl.wel1.ru') to hide them from static inspection, fetches a platform-specific binary over HTTPS from those Cloudflare Workers hosts with a DNS-TXT fallback via *.dl.wel1.ru, writes it to a masqueraded path (/var/tmp/.cache_<uid> or %TEMP%/dotnet_diag_<uid>.exe), chmods it 0755, and detach-spawns it via cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true}) or the cmd equivalent on Windows. A TTL marker suppresses re-execution. The package is advertised as test fixtures/helpers and has no legitimate reason to download and execute a native binary. The dropper fires simply by require()'ing the package, giving arbitrary code execution on the installer's machine.\n","affected":[{"package":{"name":"devplatform-test-pvm-is-even","ecosystem":"npm","purl":"pkg:npm/devplatform-test-pvm-is-even"},"versions":["35.9.5"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_runtime.js","sha256":"dfd05aa72cb2c674f0b921cd3d63f170148741a1a3e1db17ea9c9c2df71f89d9","tlsh":"40a1975a05aa70198bb0d7e487174816f65bf6633381c298fb6c55981f7712883b2efc"}],"package_integrity":[{"filename":"devplatform-test-pvm-is-even-35.9.5.tgz","hashes":{"sha1":"1214d92ef371695b2e04819c2d61062a1802df7e","sha512_sri":"sha512-DuF4ojiKD7+zAc8oHmX2xzjBP35zPCBmoMJeGWb5upMiizYZjcAnhw5IUkB4IQl2FTyIoU5XfLFlA+avj4V7YQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-test-pvm-is-even/MAL-2026-13267.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-test-pvm-is-even/v/35.9.5"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015734","import_time":"2026-08-05T16:13:37.848160346Z","modified_time":"2026-08-05T15:31:51Z","sha256":"4ab114c230ec1d462306a74f0eaaddf32474b1fae0087e1038ab2e280637d558","source":"amazon-inspector","versions":["35.9.5"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}