Malicious code in devplatform-spa-plugin-s3-module-loader (npm)
MAL-2026-12779
Published · Modified
Description
__
Source: amazon-inspector (b1a4f4ab19296a9ece2741e6f813780cbdc84d5f7fe188024ad2deb51aa97b5a)
On require of the package's main entry, index.js loads adapter.js, which selects a platform-specific payload URL, fetches opaque bytes from one of three obfuscated Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) assembled from split string arrays, writes them to a hidden temp path (dot-file on Unix, dotnet_diag*.exe on Windows), chmods 0755 on Unix, and spawns the file detached via /bin/sh -c or cmd.exe /c start. A DNS-over-TXT fallback resolves c.
Ready to move
Start Securing
Free, no credit card | First findings in minutes