OpenSSF/OSV advisory MAL-2026-12737 confirms this npm version as malicious. devplatform-react-micro-frontend@35.2.1 is a lure package whose main entry auto-loads _adapter.js on require. _adapter.js selects a platform-specific asset, downloads an opaque binary over HTTPS from a rotating list of Cloudflare *.workers.dev hosts (oob-worker.cf101-adf.workers.dev and siblings cf100/cf102/cf103), and if HTTPS fails reassembles up to 2000 numbered TXT records under *.dl.wel1.ru into a base64...
Source downloads or fetches remote code and executes it.
_adapter.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_adapter.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgSource downloads or fetches remote code and executes it.
_adapter.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_adapter.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg