Logo
npm

devplatform-spa-plugin-error-boundary@35.4.6

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:37 AM UTC

Malicious

OSV ID

MAL-2026-12766

Ecosystem

npm

Summary

The package's main index.js unconditionally requires./_ext, which runs at load time and fetches a per-platform binary over HTTPS from string-concatenation-obfuscated Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev). If HTTPS fails, _ext.js falls back to a DNS TXT covert channel under *.dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), querying c.<domain> for a chunk count then 0.<domain>, 1.<domain>,... and base64-decoding the concatenation into a binary. The fetched bytes are written to a randomly-named file in the temp directory (masquerading as.cache_<hex>, dotnet_diag_<hex>.exe, analytics_state), chmod'd 0755, and spawned detached via /bin/sh -c or cmd /c start /b. There is no version pinning, hash verification, or publisher-owned CDN, and the package's stated purpose (an SPA error-boundary component) has no legitimate reason to fetch and execute a native binary. Endpoint hostnames are assembled from split array literals at runtime to defeat static string scanning. Loading this package causes arbitrary attacker-controlled code to run on the installer's host.

Source: amazon-inspector (282ec333b26c6283eb35916acab1db10c1362d296d0694b1548882c6e48c06be)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.