Malicious code in devplatform-react-utils (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (15880efb2feec5e49ab725414e805293700e451ede11a2e4f3b1fe8e2f8f881c) On require of the package, index.js loads _helpers.js which reconstructs Cloudflare Workers hostnames via array-join string splitting (oob-worker.cf{99-9b3,101-adf,102-baf,103-070}.workers.dev), downloads a platform-specific binary, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start. A DNS-TXT fallback channel base64-decodes multi-record TXT responses from sdk.dl.wel1.ru into the payload bytes. lib/telemetry.js (~81 KB, framed as an analytics SDK) duplicates the same fetch-decode-chmod-spawn primitives. Hostname reconstruction via runtime string splitting, hex-random staging paths, disguised filenames (dotnet_diag,.cache_,.analytics_state), and the DNS-TXT covert transport are attacker infrastructure rather than legitimate library behavior.
Malicious code in devplatform-react-utils (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (15880efb2feec5e49ab725414e805293700e451ede11a2e4f3b1fe8e2f8f881c) On require of the package, index.js loads _helpers.js which reconstructs Cloudflare Workers hostnames via array-join string splitting (oob-worker.cf{99-9b3,101-adf,102-baf,103-070}.workers.dev), downloads a platform-specific binary, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start. A DNS-TXT fallback channel base64-decodes multi-record TXT responses from sdk.dl.wel1.ru into the payload bytes. lib/telemetry.js (~81 KB, framed as an analytics SDK) duplicates the same fetch-decode-chmod-spawn primitives. Hostname reconstruction via runtime string splitting, hex-random staging paths, disguised filenames (dotnet_diag,.cache_,.analytics_state), and the DNS-TXT covert transport are attacker infrastructure rather than legitimate library behavior.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12743
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735739bf8831d53914e193
Added to database: 08/05/2026, 15:31:05 UTC
Last updated: 08/05/2026, 15:31:05 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.