MAL-2026-13546
Malicious code in devplatform-spa-plugin-feature-toggle (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (2d61b9d430e59b37ce3c13873e37c1dd146d468b6a06f462761e2214acd1d0fa) devplatform-spa-plugin-feature-toggle@35.7.4 executes attacker-controlled code on the installer's host at module import. The package's main entry loads _support.js, which builds three hardcoded origins under *.workers.dev (oob-worker.cf101/cf102/cf103-*) by array-join concatenation to evade string scanning, with a DNS-TXT base64-chunked fallback under *.dl.wel1.ru. It downloads an OS-specific binary, writes it to /var/tmp/.cache_<rnd> on Unix or %TEMP%/dotnet_diag_<rnd>.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. Cover-story naming ("analytics_state", "telemetry", "dotnet_diag") does not match the package's advertised feature-toggle purpose. A sibling file lib/telemetry.js contains a larger variant of the same drop-and-exec primitives framed as an "Analytics SDK", not currently reached from main. The destination origins are anonymous Cloudflare Workers and a DDNS-style host, not a publisher-owned domain, and the delivered payload is an opaque executable with no pinning or integrity check.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for devplatform-spa-plugin-feature-toggle (npm). Pin to a known-safe version or switch to an alternative.