Logo
npm

devplatform-api-clients@35.6.8

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 11:33 AM UTC

Malicious

OSV ID

MAL-2026-12691

Ecosystem

npm

Summary

index.js unconditionally requires./setup.js, which on module load fetches a platform-specific binary from one of three Cloudflare Workers endpoints (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev), with a DNS TXT-record fallback across sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The endpoints are concealed by splitting the hostnames into string arrays that are joined at runtime. The downloaded binary is written to /tmp or %TEMP% under stealth names such as dotnet_diag_<rand>.exe or.cache_<rand> (setup.js line ~119), chmod 0755'd, and spawned detached via spawn('/bin/sh', ['-c', fp+' &']).unref() or the cmd equivalent. A marker file gates re-execution and DISABLE_TELEMETRY / DO_NOT_TRACK env vars are honored as a plausible-deniability cover. The package advertises itself as a service-client SDK; a client SDK has no need to fetch and execute an opaque native binary from a third-party edge host at require time.

Source: amazon-inspector (e548a0e6be161acd612b2729edd26e431f1bc4405e625daf957ede88db94e017)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.