{"id":"MAL-2026-10728","summary":"Malicious code in bvm-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (87ff2c7d903c5594ba5fa2e11d3fe6281380a5f2d010a1a0e3c0679464ab1fca)\ndist/index.js in bvm-core@1.1.43 imports child_process and issues fetch() calls to the hardcoded host https://bvm-core.nexsail.top at the top of the bundled module, alongside a secondary fetch to registry.npmmirror.com. The combination — a lookalike domain that mirrors the package name on an unrelated TLD, module-load-time network calls, and child_process usage in the same bundle — is the fingerprint of an install/import-time beacon and command execution channel, not a legitimate SDK call. The package name resembles established `bvm` version-manager tooling but the code routes traffic to an author-controlled host on nexsail.top rather than to any documented registry or vendor endpoint.\n","modified":"2026-07-16T19:19:42.939608404Z","published":"2026-07-16T18:46:49Z","database_specific":{"malicious-packages-origins":[{"sha256":"87ff2c7d903c5594ba5fa2e11d3fe6281380a5f2d010a1a0e3c0679464ab1fca","source":"amazon-inspector","versions":["1.1.43"],"id":"IN-MAL-2026-010781","import_time":"2026-07-16T18:54:04.541874387Z","modified_time":"2026-07-16T18:46:49Z"},{"source":"amazon-inspector","versions":["1.1.42"],"id":"IN-MAL-2026-010782","import_time":"2026-07-16T18:54:04.603193561Z","modified_time":"2026-07-16T18:47:00Z","sha256":"f8ba5a35e4424e78202f6d7af907dd7e46b6381b81eba8bbabb126a2e02579c1"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bvm-core/v/1.1.43"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/bvm-core/v/1.1.42"}],"affected":[{"package":{"name":"bvm-core","ecosystem":"npm","purl":"pkg:npm/bvm-core"},"versions":["1.1.43","1.1.42"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"dist/index.js","sha256":"be83f4e63f0a2b5771601b028c761d005d434619a4fb3fc82b7a6916b6bcaf61","tlsh":"4e831916a7ff653363a87265a9160000a7b8c75b0a04d40af2fcb54a2f7c5985ef7f78"}],"package_integrity":[{"filename":"bvm-core-1.1.43.tgz","hashes":{"sha512_sri":"sha512-x3XljrU08cuASnp4e8e6fBIvU2KOIWsYA7RAD/FgW4fOYUvIejV9Hpxa4uGk5/T6h9Oerjx6qYptRZ3kNMOlhw==","sha1":"5c06c4d7acd93259c65e5458fc8e3de1024218fd"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bvm-core/MAL-2026-10728.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}