Malicious code in devplatform-spa-plugin-notifier (npm)
MAL-2026-12773
Published · Modified
Description
__
Source: amazon-inspector (877337509f36ab52fcfb93d1dc48d77439a5154d077fc047b7263265cfb71468)
On module load, index.js requires bootstrap.js which selects a platform-specific asset, downloads an opaque binary from hardcoded Cloudflare Workers subdomains (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS TXT chunked-base64 fallback via sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes it to a disguised temp path (names such as dotnet_diag* and.cache_*), chmods it 0755 on Unix, and spawns it detached via /bin/sh -c or cmd /c start. Hostnames are assembled at runtime by joining fragmented substrings to defeat string search, and telemetry-opt-out variable names (analytics_state, DISABLE_TELEMETRY) are used as cover. No hash or signature verification is performed, and the destinations bear no relationship to a 'spa plugin notifier'.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes