Malicious code in devplatform-select-user (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (e2f7e22a3a99d2447b8bc3e6c0b1f4a92077ce570fdacff421e9fdee6a83e723) On require(), the package loads _bridge.js which downloads a platform-specific binary over HTTPS from hardcoded Cloudflare Workers mirrors (oob-worker.cf99-9b3.workers.dev, cf101-adf.workers.dev, cf102-baf.workers.dev), writes it to /var/tmp or %TEMP% under cover-story names such as.cache_<hex> and dotnet_diag_<hex>.exe, chmods it 0755, and spawns it detached via cp.spawn('/bin/sh', ['-c', fp+' &']) on POSIX or cmd on Windows. Destination hostnames are reconstructed at runtime from split character arrays (['oob-worker.cf99-9b3.worke','rs.','de','v'].join('')) to evade string-based scanners. A DNS fallback channel resolves TXT records under *.dl.wel1.ru (assembled the same way in _DNS_MAP) to retrieve or exfiltrate chunked data when HTTPS is blocked. The package's advertised purpose is a 'select user' UI helper — there is no functional reason for it to fetch and execute an opaque native binary from anonymous Cloudflare Workers subdomains at import time. Cover-story comments ('Shuffle endpoints to distribute load', 'Clean up temporary files') and a DISABLE_TELEMETRY opt-out gate frame the dropper as diagnostics. Installing or importing this package results in attacker-controlled code executing on the host.
Malicious code in devplatform-select-user (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (e2f7e22a3a99d2447b8bc3e6c0b1f4a92077ce570fdacff421e9fdee6a83e723) On require(), the package loads _bridge.js which downloads a platform-specific binary over HTTPS from hardcoded Cloudflare Workers mirrors (oob-worker.cf99-9b3.workers.dev, cf101-adf.workers.dev, cf102-baf.workers.dev), writes it to /var/tmp or %TEMP% under cover-story names such as.cache_<hex> and dotnet_diag_<hex>.exe, chmods it 0755, and spawns it detached via cp.spawn('/bin/sh', ['-c', fp+' &']) on POSIX or cmd on Windows. Destination hostnames are reconstructed at runtime from split character arrays (['oob-worker.cf99-9b3.worke','rs.','de','v'].join('')) to evade string-based scanners. A DNS fallback channel resolves TXT records under *.dl.wel1.ru (assembled the same way in _DNS_MAP) to retrieve or exfiltrate chunked data when HTTPS is blocked. The package's advertised purpose is a 'select user' UI helper — there is no functional reason for it to fetch and execute an opaque native binary from anonymous Cloudflare Workers subdomains at import time. Cover-story comments ('Shuffle endpoints to distribute load', 'Clean up temporary files') and a DISABLE_TELEMETRY opt-out gate frame the dropper as diagnostics. Installing or importing this package results in attacker-controlled code executing on the host.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12752
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735739bf8831d53914e363
Added to database: 08/05/2026, 15:31:05 UTC
Last updated: 08/05/2026, 15:39:20 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.