Malicious code in devplatform-spa-plugin-cobrowsing (npm)
MAL-2026-12763
Published · Modified
Description
__
Source: amazon-inspector (96860be3701b6237d300a1c6e6bc23ff724f14557543451e221b255aff08a29e)
On require() of the package, index.js loads runtime.js which selects a platform-specific endpoint, downloads an opaque binary over HTTPS from obfuscated Cloudflare Workers hosts (hostnames assembled at runtime via array-join, e.g. 'oob-worker.cf
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes