MAL-2026-12782
Malicious code in devplatform-spa-plugin-thermostat (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (fe54d9f541a205ad779acf3da6216c85ec0e20b6a502aaff03dc88b7cf2d85c7) On require, index.js loads _compat.js which selects a per-platform payload path, downloads a binary over HTTPS from rotating Cloudflare Workers subdomains under oob-worker.cfNNN-XXX.workers.dev (host strings reassembled from split arrays such as ["oob-worker.cf100-416.","work","er","s.","dev"].join("")) with a DNS-TXT base64-chunk fallback under *.dl.wel1.ru, writes it to /var/tmp or %TEMP% under masquerading names (dotnet_diag_<rand>.exe,.cache_<rand>,.analytics_state), chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe. No hash or signature verification is performed. Additional obfuscation reconstructs the child_process require via 'child_' + 'process' concatenation. The package is published as a 'thermostat SPA plugin' but the fetched binary and infrastructure have no relation to that stated purpose.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for devplatform-spa-plugin-thermostat (npm). Pin to a known-safe version or switch to an alternative.