Logo
npm

devplatform-data-table@35.4.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 2:37 AM UTC

Malicious

OSV ID

MAL-2026-12708

Ecosystem

npm

Summary

On require('devplatform-data-table'), index.js loads _ext.js inside a swallowed try/catch. _ext.js reconstructs a rotating list of Cloudflare Workers hostnames (oob-worker.cf10{0..3}-*.workers.dev) and a DNS TXT fallback via *.dl.wel1.ru by string-splitting fragments to evade static scanners, downloads a platform-specific binary via https.get, writes it to /tmp/.cache_<hex> on POSIX or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe with unref(). The download destination has no version pin or hash check and is unrelated to the package's stated data-table purpose; the cover-story filenames (dotnet_diag,.cache,.analytics_state) and split-join hostname construction indicate deliberate concealment. A second file lib/telemetry.js ships the same drop-and-execute primitives (base64 chunk decode, cp.spawn('/bin/sh', ['-c', filePath + ' &'], {detached}), fs['chmod'+'Sync']) under an 'Analytics SDK' framing.

Source: amazon-inspector (4d9d428dae035b88a4c025d9edd346d22cf2dffbb5a21ae597560702280b3949)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.