-= Per source details. Do not edit below this line.=-
The package presents as a devkit for the Nx ecosystem but ships a trivial no-op class in index.js alongside a hidden shim.js. On require, index.js unconditionally invokes require('./shim'), which reconstructs destination hostnames via array-join over split fragments (assembling oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, with a DNS TXT fallback channel through sdk/ext/pkg/net.dl.wel1.ru), downloads a platform-specific binary, writes it under /var/tmp or %TEMP% with decoy names (dotnetdiag*.exe,.analyticsstate,.cache*), chmods 0755, and detached-spawns it via /bin/sh -c or cmd. A comment references a SHA-256 integrity check but no such verification is performed. Opt-out environment variables (DISABLETELEMETRY, ANALYTICSOPTOUT, DONOT_TRACK) and a sibling lib/telemetry.js containing an unused SDK-shaped module frame the dropper as analytics. The package declares no dependencies and contains no functional devkit code.
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T13:48:49Z",
"id": "IN-MAL-2026-015049",
"import_time": "2026-08-05T14:19:56.560780732Z",
"sha256": "cc4017373371f50665290c944ee840b2ad4a7e745dcb5eb973f977185b150ac7",
"versions": [
"35.8.5"
]
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-nx-devkit/MAL-2026-12722.json"
{
"package_integrity": [
{
"filename": "devplatform-nx-devkit-35.8.5.tgz",
"hashes": {
"sha512_sri": "sha512-7D7Epf7st+ywFla7OIn7inV6jCaj5ulqDcMInJQgyNLS8eWe/Gr+HCVQjhh86crpqFd4cw0GdXncq2OjZb3AOA==",
"sha1": "1bebed3bc07abf0dc082772e3f91f3c2ab22fd82"
}
}
],
"evidence_files": [
{
"tlsh": "56b1869a16aa70198bb0dbf487175426f55af6633380c184fb5ca5885f7712483b1dfc",
"sha256": "a03e72c36c77203b0e06f815143e47ef99d55ea8ccc7fda7914a4ce67bf12ed8",
"path": "_shim.js"
},
{
"tlsh": "bcf0fc9716daec72877463a3daf21051f5a284315f47415c759850de0ba0c5002adfba",
"sha256": "50566421a228acf2b8d3c3e1161edae0960c9cb66309f256d509af0dc181edc7",
"path": "index.js"
}
]
}
[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]