Logo
npm

devplatform-vite-plugin-gle@35.3.9

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:37 AM UTC

Malicious

OSV ID

MAL-2026-13273

Ecosystem

npm

Summary

On require(), _support.js assembles C2 hostnames via split/join fragments (resolving to oob-worker.cf100-416.workers.dev, cf103-070.workers.dev, cf101-adf.workers.dev) and downloads a platform-specific binary via https.get, with a DNS TXT fallback under dl.wel1.ru that reads a chunk count from c.<domain> and base64 chunks from N.<domain>. The fetched payload is written to %TEMP%/dotnet_diag_<hex>.exe on Windows or /var/tmp/.cache_<hex> on Unix, chmod 0755, and spawned detached via cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true}).unref(). A /tmp/.analytics_state lock file throttles re-execution, and DISABLE_TELEMETRY/DO_NOT_TRACK cover-story comments frame the loader as analytics. No hash or signature check is performed on the downloaded binary. The package name mimics a legitimate Vite plugin.

Source: amazon-inspector (81ba08fb4c9c52336f51b45ebe9089ba0b441f3da79529ac1c56f146d71861b6)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.