Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

devplatform-spa-tokensnpm

devplatform-spa-tokens is a confirmed malicious npm package (MAL-2026-12785) that steals credentials and exfiltrates sensitive data (malicious version 35.3.1). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in devplatform-spa-tokens (npm)

MAL-2026-12785
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall devplatform-spa-tokens

What this malware does

On require(), index.js loads support.js, which assembles Cloudflare Workers hostnames (oob-worker.cf*.workers.dev) and fallback domain sdk.dl.wel1.ru at runtime from split string arrays joined via.join(""), downloads a platform-specific binary from those hosts (with a DNS TXT chunked fallback via c.<domain>/i.<domain> records when HTTPS is blocked), writes the payload to a temp path with a disguised name (e.g. dotnet_diag<rand>.exe,.cache_<rand>), chmods 0755 on POSIX, and spawns it detached via spawn("/bin/sh") or spawn("cmd"). Execution is gated by DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK env vars and a /tmp/.analytics_state cache, framing the dropper as analytics. The advertised TokenManager API is a decoy — no relation to the download-and-execute behavior. Destination hosts are anonymous workers.dev / lookalike infrastructure, not the package's stated purpose or publisher.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

1 flagged
35.3.1

Indicators of compromise (SHA-256)

6127d0c2ccf2b21fdd6f22244b040c905b2296c86c47cc3c4eb012b61a4c455a
0b2287b5f70bc9779abda2839f7d2e2227ec977e332d78d5ae5da19b84a0a143

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for devplatform-spa-tokens (version 35.3.1). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging devplatform-spa-tokens across your stack and pipelines.

  2. If you installed it — respond

    devplatform-spa-tokens is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If devplatform-spa-tokens was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks devplatform-spa-tokens before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. devplatform-spa-tokens on npm has been identified as a malicious package (version 35.3.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-014996GHSA-67wj-rrpv-vxwq

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks devplatform-spa-tokens-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

devplatform-spa-tokens (npm) malicious package — MAL-2026-12785 | O3 Security