CRITICAL npm Malware

Malicious code in devplatform-spa-feature-toggle (npm)

MAL-2026-12758

Published · Modified

Description


__

Source: amazon-inspector (50ddc07faa8afae95b4e759f77938829d91d2b548d2606c325555b0900fe61f1)

On require() of the package, index.js loads bridge.js, which selects a per-OS payload path, fetches an executable from a list of Cloudflare Workers hosts assembled via runtime string-splitting (e.g. ["oob-worker.cf101-adf.workers",".de","v"].join("")) with a DNS-TXT chunked-base64 fallback to hosts such as sdk.dl.wel1.ru, writes the payload to /var/tmp or %TEMP% under decoy names like.cache or dotnet_diag_.exe, chmods it 0755, and spawns it detached via /bin/sh -c or cmd with stdio ignored. Additional cover-story markers include a.analytics_state marker file and DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK env gates. The destination hosts are not the package's publisher infrastructure and the fetched bytes are opaque and executed without integrity verification.

Ready to move

Start Securing

Free, no credit card | First findings in minutes