LWA-2026-10254 MAL-2026-12783 ↗ confirmed malware

devplatform-spa-route-tree@35.1.3

Malicious code in devplatform-spa-route-tree (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1102 · Web ServiceT1573 · Encrypted Channel

Analysis

On require, the package runs a multi-stage dropper. It downloads a binary over HTTPS from Cloudflare Workers hosts oob-worker[.]cf103-070[.]workers[.]dev, oob-worker[.]cf100-416[.]workers[.]dev, oob-worker[.]cf99-9b3[.]workers[.]dev, and oob-worker[.]cf102-baf[.]workers[.]dev (paths /pkg/package, /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe), with a DNS-TXT chunked fallback via c[.]sdk[.]dl[.]wel1[.]ru, ext[.]dl[.]wel1[.]ru, pkg[.]dl[.]wel1[.]ru, and net[.]dl[.]wel1[.]ru. The fetched payload is written to /var/tmp/.cache_<hex> (or dotnet_diag_<hex>.exe under the temp dir on Windows), made executable, and launched as a detached background process via /bin/sh -c "<path> &" or cmd.exe /c start /b. A state file in the temp dir throttles repeat execution. The package also ships an 81KB decoy telemetry module that is never invoked.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 01:44 PM
analyzed
Aug 5, 2026, 02:44 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.