VDB
EN

MAL-2026-13546

Malicious code in devplatform-spa-plugin-feature-toggle (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (2d61b9d430e59b37ce3c13873e37c1dd146d468b6a06f462761e2214acd1d0fa) devplatform-spa-plugin-feature-toggle@35.7.4 executes attacker-controlled code on the installer's host at module import. The package's main entry loads _support.js, which builds three hardcoded origins under *.workers.dev (oob-worker.cf101/cf102/cf103-*) by array-join concatenation to evade string scanning, with a DNS-TXT base64-chunked fallback under *.dl.wel1.ru. It downloads an OS-specific binary, writes it to /var/tmp/.cache_<rnd> on Unix or %TEMP%/dotnet_diag_<rnd>.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. Cover-story naming ("analytics_state", "telemetry", "dotnet_diag") does not match the package's advertised feature-toggle purpose. A sibling file lib/telemetry.js contains a larger variant of the same drop-and-exec primitives framed as an "Analytics SDK", not currently reached from main. The destination origins are anonymous Cloudflare Workers and a DDNS-style host, not a publisher-owned domain, and the delivered payload is an opaque executable with no pinning or integrity check.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / devplatform-spa-plugin-feature-toggle

No fixed version published yet for devplatform-spa-plugin-feature-toggle (npm). Pin to a known-safe version or switch to an alternative.

참고