devplatform-react-form @35.8.3
Vulnerability report · Last retrieved from osv.dev August 8, 2026 at 7:15 PM UTC
OSV ID
MAL-2026-12735
Ecosystem
npm
Summary
On require('devplatform-react-form'), index.js loads _adapter.js which fetches a platform-specific native binary from hardcoded Cloudflare Workers endpoints (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS-TXT chunked fallback via sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes the payload to /tmp or %TEMP% under deceptive names (.cache_<hex>, dotnet_diag_<hex>.exe), chmods it 0o755, and spawns it detached via cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true, stdio:'ignore'}).unref(), using a stamp file to avoid re-execution. Host and API strings are assembled from split fragments (e.g. ["oob-worker.cf102-baf.wo","rk","ers.de","v"].join(""), require('child_'+'process')) to evade static analysis. lib/telemetry.js contains a parallel dropper under an 'Analytics SDK' cover story using the same base64-chunk-decode + chmod 0o755 + cp.spawn('/bin/sh',...) pattern. The package advertises itself as a React form library but ships no form code; the fetched binary is unrelated to any documented purpose and delivers full-host code execution to any process that imports the module.
Source: amazon-inspector (422556511a13a0424a33cfdb404a289d3fd51a0f7f206b4de8114fe69a0874b6)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.