CRITICAL npm Malware

Malicious code in devplatform-spa-plugin-thermostat (npm)

MAL-2026-12782

Published · Modified

Description


__

Source: amazon-inspector (fe54d9f541a205ad779acf3da6216c85ec0e20b6a502aaff03dc88b7cf2d85c7)

On require, index.js loads compat.js which selects a per-platform payload path, downloads a binary over HTTPS from rotating Cloudflare Workers subdomains under oob-worker.cfNNN-XXX.workers.dev (host strings reassembled from split arrays such as ["oob-worker.cf100-416.","work","er","s.","dev"].join("")) with a DNS-TXT base64-chunk fallback under *.dl.wel1.ru, writes it to /var/tmp or %TEMP% under masquerading names (dotnet_diag.exe,.cache_,.analytics_state), chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe. No hash or signature verification is performed. Additional obfuscation reconstructs the child_process require via 'child_' + 'process' concatenation. The package is published as a 'thermostat SPA plugin' but the fetched binary and infrastructure have no relation to that stated purpose.

Ready to move

Start Securing

Free, no credit card | First findings in minutes