{"id":"MAL-2026-12059","summary":"Malicious code in bcore-bravo-eslint-config (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fe55f411284226c68e60cbcae266a390a3ba0ef089a2a709363df3188130f605)\nThe package presents itself as an ESLint config / 'environment config reader' but on require() executes an import-time dropper. index.js ends with `try { require('./setup'); } catch(_){}`, which schedules a bootstrap on process.nextTick. setup.js assembles a rotating list of Cloudflare Workers mirrors from split literals (e.g. `[\"package-proxy.cf5oob\",\"wor\",\"ker.\",\"wor\",\"kers\",\".dev\"]`, and cf8/cf12/cf17/cf25 siblings), plus a `*.dl.well1.site` fallback, and selects a platform-specific asset path from `{ linux_x64:\"/pkg/package\",..., darwin_arm64:\"/pkg/package-arm64\", darwin:\"/pkg/loader_mac\", win32:\"/pkg/package.exe\" }`. lib/telemetry.js fetches the response, base64-decodes it (`Buffer.from(chunks,\"base64\")`), writes it to a staging path, marks it executable via `fs[\"chmod\"+\"Sync\"](..., 0o755)`, and executes it via `require(\"child_\"+\"process\")`. Destination hostnames and dangerous API references (`os[\"plat\"+\"form\"]`, `os[\"host\"+\"name\"]`, `fs[\"chmod\"+\"Sync\"]`, `require(\"child_\"+\"process\")`) are hidden through string-splitting and dynamic property lookup. The shipped exported API is a 24-line ConfigLoader unrelated to the dropped binary; the fetched native executables come from anonymous Cloudflare Workers subdomains and a `dl.well1.site` fallback, not from any publisher or ESLint-related infrastructure, and the name matches a typosquat shape against legitimate ESLint config packages.\n","modified":"2026-08-05T03:20:46.052035730Z","published":"2026-08-05T01:47:41Z","database_specific":{"malicious-packages-origins":[{"versions":["12.5.7"],"id":"IN-MAL-2026-011530","import_time":"2026-08-05T03:11:17.976526728Z","modified_time":"2026-08-05T01:48:00Z","sha256":"121c404b778f379999022d0b92e68ae7e8fd2663d1731b03af8e87cad3037676","source":"amazon-inspector"},{"versions":["9.5.7"],"id":"IN-MAL-2026-011528","import_time":"2026-08-05T03:11:17.769340553Z","modified_time":"2026-08-05T01:47:41Z","sha256":"30f16ba2b7357ecd393b34c006561c8642786667af55222b928b3b003f6c17ed","source":"amazon-inspector"},{"versions":["9.5.9"],"id":"IN-MAL-2026-011531","import_time":"2026-08-05T03:11:18.070690455Z","modified_time":"2026-08-05T01:48:08Z","sha256":"3bae1e6300947d81c5442b4931ad570867c66bc9ddbb04888a875a0b3e33e636","source":"amazon-inspector"},{"source":"amazon-inspector","versions":["9.5.8"],"id":"IN-MAL-2026-011529","import_time":"2026-08-05T03:11:17.855977831Z","modified_time":"2026-08-05T01:47:53Z","sha256":"cea299913e6482aa04435c1a0b13864466ac9a96a6d74d87dacd6d2dfc731386"},{"versions":["9.5.6"],"id":"IN-MAL-2026-011532","import_time":"2026-08-05T03:11:18.16827127Z","modified_time":"2026-08-05T01:48:15Z","sha256":"fe55f411284226c68e60cbcae266a390a3ba0ef089a2a709363df3188130f605","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bcore-bravo-eslint-config/v/12.5.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/bcore-bravo-eslint-config/v/9.5.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/bcore-bravo-eslint-config/v/9.5.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/bcore-bravo-eslint-config/v/9.5.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/bcore-bravo-eslint-config/v/9.5.6"}],"affected":[{"package":{"name":"bcore-bravo-eslint-config","ecosystem":"npm","purl":"pkg:npm/bcore-bravo-eslint-config"},"versions":["12.5.7","9.5.7","9.5.9","9.5.8","9.5.6"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bcore-bravo-eslint-config/MAL-2026-12059.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-X7zIH7GfdpjPgdQqxwrNk4ZpEUjA4vY8bG2dzClN8CULZCzdl1w/1UbqQgNE3YuQPB0g7W+CFe9TiTX4nR6AnQ==","sha1":"de2cda800ae79ebf492b1c73e5672c41c99e1cd1"},"filename":"bcore-bravo-eslint-config-12.5.7.tgz"}],"evidence_files":[{"sha256":"8f0408a8a36dac6c84b61ce497abe4e97fbec7aa75120b387894e005dff29ac7","tlsh":"17b1a4550afa71384392a1e8d92b5816b09fe5533284e990f34cb6985f97268c3b39fc","path":"setup.js"},{"path":"index.js","sha256":"a4b1c1434cade6ae9ec65ba276e9a4c53bccdeaa620f403b043565db588183ea","tlsh":"6e11b1a097caf6d386b067d28d2a0413fd5bc9262244929874dcb0de3f6942041a3ff8"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}