Malicious code in devplatform-spa-plugin-feature-toggle (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (2d61b9d430e59b37ce3c13873e37c1dd146d468b6a06f462761e2214acd1d0fa) [email protected] executes attacker-controlled code on the installer's host at module import. The package's main entry loads _support.js, which builds three hardcoded origins under *.workers.dev (oob-worker.cf101/cf102/cf103-*) by array-join concatenation to evade string scanning, with a DNS-TXT base64-chunked fallback under *.dl.wel1.ru. It downloads an OS-specific binary, writes it to /var/tmp/.cache_<rnd> on Unix or %TEMP%/dotnet_diag_<rnd>.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. Cover-story naming ("analytics_state", "telemetry", "dotnet_diag") does not match the package's advertised feature-toggle purpose. A sibling file lib/telemetry.js contains a larger variant of the same drop-and-exec primitives framed as an "Analytics SDK", not currently reached from main. The destination origins are anonymous Cloudflare Workers and a DDNS-style host, not a publisher-owned domain, and the delivered payload is an opaque executable with no pinning or integrity check.
Malicious code in devplatform-spa-plugin-feature-toggle (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (2d61b9d430e59b37ce3c13873e37c1dd146d468b6a06f462761e2214acd1d0fa) [email protected] executes attacker-controlled code on the installer's host at module import. The package's main entry loads _support.js, which builds three hardcoded origins under *.workers.dev (oob-worker.cf101/cf102/cf103-*) by array-join concatenation to evade string scanning, with a DNS-TXT base64-chunked fallback under *.dl.wel1.ru. It downloads an OS-specific binary, writes it to /var/tmp/.cache_<rnd> on Unix or %TEMP%/dotnet_diag_<rnd>.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. Cover-story naming ("analytics_state", "telemetry", "dotnet_diag") does not match the package's advertised feature-toggle purpose. A sibling file lib/telemetry.js contains a larger variant of the same drop-and-exec primitives framed as an "Analytics SDK", not currently reached from main. The destination origins are anonymous Cloudflare Workers and a DDNS-style host, not a publisher-owned domain, and the delivered payload is an opaque executable with no pinning or integrity check.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13546
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a75f710bf8831d53984fa98
Added to database: 08/07/2026, 15:17:36 UTC
Last updated: 08/07/2026, 15:17:36 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.