Malicious code in devplatform-api-v2-endpoint (npm)
The devplatform-api-v2-endpoint npm package version 35.6.7 contains malicious code that executes arbitrary attacker-controlled binaries on the host system upon import. The package loads a platform-specific native binary from Cloudflare Workers hosts or reconstructs it from DNS TXT records, writes it to temporary directories with misleading filenames, sets executable permissions, and executes it detached from the main process. The malicious activity is disguised as telemetry or analytics functionality.
AI Analysis
Technical Summary
The devplatform-api-v2-endpoint npm package (version 35.6.7) includes a malicious component that, when required, loads a platform-specific native binary from runtime-assembled Cloudflare Workers hosts or reconstructs it from DNS TXT records. This binary is saved to temporary directories under deceptive filenames, given executable permissions, and executed in a detached manner via shell commands. The command and control hostnames are obfuscated by splitting string fragments to evade static detection. This results in arbitrary attacker-controlled code execution on the host system every time the package is imported.
Potential Impact
This malicious package enables arbitrary code execution on the installer's host system, potentially allowing attackers to run any code with the privileges of the user importing the package. This can lead to full system compromise, data theft, persistence, or further lateral movement depending on the environment and privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix or official guidance is available, avoid using version 35.6.7 of devplatform-api-v2-endpoint. Remove the package from all environments and audit systems for signs of compromise related to this package. Consider blocking network access to the identified Cloudflare Workers hosts and DNS domains used for binary retrieval as a temporary mitigation.
Malicious code in devplatform-api-v2-endpoint (npm)
Description
The devplatform-api-v2-endpoint npm package version 35.6.7 contains malicious code that executes arbitrary attacker-controlled binaries on the host system upon import. The package loads a platform-specific native binary from Cloudflare Workers hosts or reconstructs it from DNS TXT records, writes it to temporary directories with misleading filenames, sets executable permissions, and executes it detached from the main process. The malicious activity is disguised as telemetry or analytics functionality.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The devplatform-api-v2-endpoint npm package (version 35.6.7) includes a malicious component that, when required, loads a platform-specific native binary from runtime-assembled Cloudflare Workers hosts or reconstructs it from DNS TXT records. This binary is saved to temporary directories under deceptive filenames, given executable permissions, and executed in a detached manner via shell commands. The command and control hostnames are obfuscated by splitting string fragments to evade static detection. This results in arbitrary attacker-controlled code execution on the host system every time the package is imported.
Potential Impact
This malicious package enables arbitrary code execution on the installer's host system, potentially allowing attackers to run any code with the privileges of the user importing the package. This can lead to full system compromise, data theft, persistence, or further lateral movement depending on the environment and privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix or official guidance is available, avoid using version 35.6.7 of devplatform-api-v2-endpoint. Remove the package from all environments and audit systems for signs of compromise related to this package. Consider blocking network access to the identified Cloudflare Workers hosts and DNS domains used for binary retrieval as a temporary mitigation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12694
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735737bf8831d539147060
Added to database: 08/05/2026, 15:31:03 UTC
Last enriched: 08/05/2026, 16:27:23 UTC
Last updated: 08/05/2026, 16:27:23 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.