devplatform-spa-plugin-s3-module-loader@35.8.2
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-12779
Ecosystem
npm
Summary
On require of the package's main entry, index.js loads _adapter.js, which selects a platform-specific payload URL, fetches opaque bytes from one of three obfuscated Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) assembled from split string arrays, writes them to a hidden temp path (dot-file on Unix, dotnet_diag_*.exe on Windows), chmods 0755 on Unix, and spawns the file detached via /bin/sh -c or cmd.exe /c start. A DNS-over-TXT fallback resolves c.<domain>/i.<domain> under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru and base64-reassembles a payload from numbered TXT records when HTTPS delivery is blocked. Destinations, delivery channels, and payloads are fully author-controlled, obfuscated via runtime string reassembly, and unrelated to the package's advertised S3-module-loader purpose. Cover-story identifiers include analytics_state and DISABLE_TELEMETRY.
Source: amazon-inspector (b1a4f4ab19296a9ece2741e6f813780cbdc84d5f7fe188024ad2deb51aa97b5a)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.