-= Per source details. Do not edit below this line.=-
On require('devplatform-cli-spa'), index.js loads support.js which selects a payload by OS and architecture, downloads a native binary over HTTPS from string-obfuscated Cloudflare Workers hostnames (oob-worker.cf1-01-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS TXT base64 fallback served from *.dl.wel1.ru. The fetched bytes are written to /tmp/.cache<rnd> on Unix or %TEMP%/dotnetdiag<rnd>.exe on Windows, chmod'd to 0755, and executed detached via spawn('/bin/sh', ['-c',...]) or spawn('cmd', ['/c', 'start',...]). The C2 hostnames and the DNS fallback domains are assembled at runtime by joining split string fragments (NODES and DNSHOSTS arrays) to evade static string matching. The Windows drop path uses a 'dotnetdiag' decoy filename, and a stamp file gates re-runs across installs.
{
"malicious-packages-origins": [
{
"sha256": "1bb41284069ba395bf67ceb847dc579c7a79c753ea89107116e91559ebbece2a",
"source": "amazon-inspector",
"import_time": "2026-08-05T14:19:58.792874325Z",
"modified_time": "2026-08-05T13:51:46Z",
"versions": [
"35.7.8"
],
"id": "IN-MAL-2026-015070"
}
]
}{
"package_integrity": [
{
"hashes": {
"sha1": "3c7db4f2edf8595836aacf43f10a90e753de14dc",
"sha512_sri": "sha512-YXG+U/CQ3jQWhwfiIsYsZ0GGbnE4YNWaLMCZmfdwBJxb6UORFZXGXH7dDpilxSgCEmzIHBYNfk55NZM2fgRh6g=="
},
"filename": "devplatform-cli-spa-35.7.8.tgz"
}
],
"evidence_files": [
{
"path": "_support.js",
"sha256": "822e7def114a07de4d365eaece31b6659dd32f43a9949e6c9739d34c04322559",
"tlsh": "35b1a796156a70198b70d7e487275416f556e6633380c2c4fb6ca5981fb6124c372efc"
}
]
}
[
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-cli-spa/MAL-2026-12704.json"