VDB
EN

MAL-2026-12782

Malicious code in devplatform-spa-plugin-thermostat (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (fe54d9f541a205ad779acf3da6216c85ec0e20b6a502aaff03dc88b7cf2d85c7) On require, index.js loads _compat.js which selects a per-platform payload path, downloads a binary over HTTPS from rotating Cloudflare Workers subdomains under oob-worker.cfNNN-XXX.workers.dev (host strings reassembled from split arrays such as ["oob-worker.cf100-416.","work","er","s.","dev"].join("")) with a DNS-TXT base64-chunk fallback under *.dl.wel1.ru, writes it to /var/tmp or %TEMP% under masquerading names (dotnet_diag_<rand>.exe,.cache_<rand>,.analytics_state), chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe. No hash or signature verification is performed. Additional obfuscation reconstructs the child_process require via 'child_' + 'process' concatenation. The package is published as a 'thermostat SPA plugin' but the fetched binary and infrastructure have no relation to that stated purpose.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / devplatform-spa-plugin-thermostat

No fixed version published yet for devplatform-spa-plugin-thermostat (npm). Pin to a known-safe version or switch to an alternative.

참고