Malicious code in devplatform-spa-plugin-module (npm)
MAL-2026-12771
Published · Modified
Description
__
Source: amazon-inspector (638c4246220ea7f9a595c145c76940e7e060920ef251ab2c67ca814b9ab93378)
On require of the package's main entry, polyfill.js executes init() which reconstructs destination hostnames via array-join string splits (e.g. ["oob-worke","r.cf100-416.worker","s.","dev"].join("")), selects a platform-specific endpoint, downloads an opaque binary via https.get from one of several Cloudflare Workers subdomains (oob-worker.cf100-416.workers.dev, cf101-adf, cf102-baf, cf103-070.workers.dev), writes the payload to /tmp or %TEMP% under a disguised name (.cache
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes