VDB
EN

MAL-2026-12041

Malicious code in platform-ui-codemods (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (1c72999be0ce122b904fcb710f5438a0d1718a3d121dd1377123c5d710aa9e27) On require() of the package, index.js loads./_compat.js whose top-level init() downloads a platform-specific binary from a set of Cloudflare Workers mirrors whose hostnames are assembled at runtime from split-string arrays joined with.join("") (e.g. oob-worker.cf1*.workers.dev), with a DNS-TXT covert-channel fallback that reconstructs a base64 payload from chunked TXT records under c.<domain>/<n>.<domain> at *.dl.well1.site (tin/tina/ldr/win subdomains). The fetched bytes are written to a hidden/decoy path ("/tmp/.cache_<hex>" on Unix, "%TEMP%\dotnet_diag_<hex>.exe" on Windows), chmod 0755, and spawned detached via /bin/sh -c or cmd.exe with a cooldown stamp file (".analytics_state") to avoid re-execution. Hostname obfuscation, decoy filenames, DNS-TXT egress fallback, and detached execution collectively indicate a staged remote-code-execution dropper that fires automatically on install/require of this package.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / platform-ui-codemods

No fixed version published yet for platform-ui-codemods (npm). Pin to a known-safe version or switch to an alternative.

참고