devplatform-data-table@35.4.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 2:37 AM UTC
OSV ID
MAL-2026-12708
Ecosystem
npm
Summary
On require('devplatform-data-table'), index.js loads _ext.js inside a swallowed try/catch. _ext.js reconstructs a rotating list of Cloudflare Workers hostnames (oob-worker.cf10{0..3}-*.workers.dev) and a DNS TXT fallback via *.dl.wel1.ru by string-splitting fragments to evade static scanners, downloads a platform-specific binary via https.get, writes it to /tmp/.cache_<hex> on POSIX or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe with unref(). The download destination has no version pin or hash check and is unrelated to the package's stated data-table purpose; the cover-story filenames (dotnet_diag,.cache,.analytics_state) and split-join hostname construction indicate deliberate concealment. A second file lib/telemetry.js ships the same drop-and-execute primitives (base64 chunk decode, cp.spawn('/bin/sh', ['-c', filePath + ' &'], {detached}), fs['chmod'+'Sync']) under an 'Analytics SDK' framing.
Source: amazon-inspector (4d9d428dae035b88a4c025d9edd346d22cf2dffbb5a21ae597560702280b3949)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.