-= Per source details. Do not edit below this line.=-
On require, index.js loads helpers.js which fetches an OS/arch-specific native binary from obfuscated Cloudflare Workers subdomains (oob-worker.cf9-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev), with a DNS-TXT covert-channel fallback under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru that reassembles a base64 payload from numbered subdomains. The fetched bytes are written to /tmp as a hidden dotfile (or to the Windows temp directory as dotnetdiag<rand>.exe), chmod 0755'd, and spawned detached via /bin/sh -c or cmd.exe. Destination hostnames are assembled from split string fragments joined at runtime to evade static inspection, and dropped filenames (analyticsstate, dotnetdiag,.cache_) impersonate unrelated system tooling. The package presents itself as a Sentry SPA plugin but has no legitimate need to download and execute a native binary from anonymous Cloudflare Workers infrastructure.
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T13:40:11Z",
"id": "IN-MAL-2026-014990",
"import_time": "2026-08-05T14:19:50.114906477Z",
"sha256": "e2827eaf1f2c14fe16fc0fcab1ad65266f275fb22a9a81237d93f8e93e84894f",
"versions": [
"35.1.1"
]
}
]
}{
"package_integrity": [
{
"filename": "devplatform-spa-plugin-sentry-35.1.1.tgz",
"hashes": {
"sha512_sri": "sha512-pVAQ0zGaJeQXuBJWAhej5GbZumm/c/1AVKnvwlN8hhEvrjQnD2GQi6U9KlqCpSNDzjUfCukBOC92tGFSXh98sA==",
"sha1": "9de0c2a9aff2b50ad8e42cd150b65b053fb78145"
}
}
],
"evidence_files": [
{
"tlsh": "d5a1a99616a6710c4bb09be487275416f65bf6633780c6c4fb5ca5981f721288372efc",
"sha256": "643642b7a0348e29f48284fbabe74ab33e1f166d2a51167651f51a96085970b2",
"path": "_helpers.js"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-spa-plugin-sentry/MAL-2026-12780.json"
[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]