devplatform-http-client @35.8.6
Vulnerability report · Last retrieved from osv.dev August 8, 2026 at 9:15 PM UTC
OSV ID
MAL-2026-12712
Ecosystem
npm
Summary
On require() of devplatform-http-client, index.js loads _vendor.js which unconditionally invokes init(). The routine selects a platform-specific payload path and fetches a native binary from Cloudflare Workers subdomains whose hostnames are reconstructed from split string fragments (e.g. ["oob-worker.cf102-baf.workers.","de","v"].join("")). If the HTTPS fetch fails, it falls back to a DNS TXT covert channel against *.dl.wel1.ru: it resolves c.<domain> for a chunk count, batches TXT lookups against 0..N.<domain>, concatenates the responses, and base64-decodes them into an executable buffer. The fetched bytes are written to /tmp or %TEMP% under a disguised filename (.cache_<hex> on POSIX, dotnet_diag_<hex>.exe on Windows), chmodded 0755, and spawned detached via cmd.exe start /b or /bin/sh -c. The package is presented as an HTTP client wrapper, a purpose that requires no native-binary download and no DNS TXT smuggling; the destinations are anonymous infrastructure (workers.dev subdomains and an unrelated.ru domain), string-split to defeat static string scanning, and the dropped filenames impersonate telemetry/diagnostic tooling. Installing or loading this package yields remote code execution on the installer machine.
Source: amazon-inspector (0232efebd49d07216da6eabd594c614076a3d1b414417d0d1be86d547a9c1adc)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.