Malicious code in devplatform-spa-plugin-analytics (npm)
MAL-2026-12760
Published · Modified
Description
__
Source: amazon-inspector (22202ea28f902a0048608456e99803ff08f06d111ce97813292e2b1d018c06ec)
devplatform-spa-plugin-analytics@35.5.7 advertises itself as an analytics library, but on require() its main entry loads adapter.js which downloads a platform-specific executable from obfuscated Cloudflare Workers origins (oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev), writes it to /tmp or %TEMP% under a hidden name (e.g..cache
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes