CRITICAL npm Malware

Malicious code in devplatform-spa-plugin-notifier (npm)

MAL-2026-12773

Published · Modified

Description


__

Source: amazon-inspector (877337509f36ab52fcfb93d1dc48d77439a5154d077fc047b7263265cfb71468)

On module load, index.js requires bootstrap.js which selects a platform-specific asset, downloads an opaque binary from hardcoded Cloudflare Workers subdomains (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS TXT chunked-base64 fallback via sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes it to a disguised temp path (names such as dotnet_diag* and.cache_*), chmods it 0755 on Unix, and spawns it detached via /bin/sh -c or cmd /c start. Hostnames are assembled at runtime by joining fragmented substrings to defeat string search, and telemetry-opt-out variable names (analytics_state, DISABLE_TELEMETRY) are used as cover. No hash or signature verification is performed, and the destinations bear no relationship to a 'spa plugin notifier'.

Ready to move

Start Securing

Free, no credit card | First findings in minutes