-= Per source details. Do not edit below this line.=-
On require() of the package, index.js loads polyfill.js which fetches a platform-specific binary from one of four Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev) with DNS TXT fallback to sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru. Hostnames are assembled at runtime from split string fragments and childprocess is loaded via require("child_"+"process") to evade static substring scanning. The downloaded binary is written to /tmp or the Windows Temp directory under a disguised name (.cache<hex> on Linux, dotnetdiag_<hex>.exe on Windows), chmod 0755 is applied through a computed "chmod"+"Sync" property lookup, and the file is spawned detached via /bin/sh -c or cmd.exe /c start /b. The package's advertised purpose is a trivial SPA tracking helper, which does not require any of this behavior. A second file, lib/telemetry.js (~81 KB, styled as a Sentry-like analytics SDK), contains an independent copy of the same fetch/chmod/spawn dropper primitives and ships as an alternate payload path in the tarball. The destination hosts are attacker-controlled, publisher-mismatched, and mutable; the executed bytes are opaque and unverified.
{
"malicious-packages-origins": [
{
"modified_time": "2026-08-05T15:31:29Z",
"source": "amazon-inspector",
"sha256": "59ba2c5091a95bcff203618393da399071dba1859bb0af79ca39021b7a1bdb5f",
"import_time": "2026-08-05T16:13:37.443289381Z",
"id": "IN-MAL-2026-015732",
"versions": [
"35.5.3"
]
}
]
}{
"package_integrity": [
{
"filename": "devplatform-spa-use-track-35.5.3.tgz",
"hashes": {
"sha512_sri": "sha512-x1ZTtiPiK/iPCoseO/tO9auZ2scnMpbnMWyRorNZZlmDfPh0ak2BLCm8+CLf4cjnienHNA49kdPv656xEf9v9w==",
"sha1": "f2d2b83acc27933ba0def993fd936888b7e2b940"
}
}
],
"evidence_files": [
{
"tlsh": "27a1879a126670184bb0d7e4c71b8826f66bf6633680c6c4f79c65945fb352483b2efc",
"sha256": "3b6e4f6258ce04214289c2982163b728a3c4586b2afd8c6a0de0f9ec706332da",
"path": "_polyfill.js"
},
{
"tlsh": "fb835055566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc",
"sha256": "e44d9ada15db2055ca512890e5d434c3922e42ad47922f1f0cb4f9136bdb82ac",
"path": "lib/telemetry.js"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/devplatform-spa-use-track/MAL-2026-13263.json"
[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]