{"id":"MAL-2026-13105","summary":"Malicious code in bpm-foundation-base-configs (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d880fad0158970d8ef9b0a0884fe6b2ceee572d3046db4cf08745d02d3c34293)\nOn require, index.js loads _helpers.js, which reconstructs C2 hostnames via string-split-join concatenation (`['oob-w','orker.cf101-adf.worke','rs','.d','ev'].join('')` and similar), selects a platform-specific payload, fetches an opaque binary from those hidden hosts over HTTPS, writes it to /tmp or the Windows temp directory under a disguised filename (`dotnet_diag_*.exe` / `.cache_*`), chmods it 0755, and spawns it detached via `/bin/sh` or `cmd.exe` (_helpers.js line 125+). If HTTPS retrieval fails, `loadViaDns` falls back to a DNS-TXT covert channel: it queries `c.\u003cdomain\u003e` for a chunk count then walks `0.\u003cdomain\u003e..N.\u003cdomain\u003e` TXT records (resolver domain reconstructed as `['sdk.dl.we','l1.r','u'].join('')`), concatenates the values, base64-decodes them into the executable buffer, and executes through the same write+chmod+spawn sink. No hash or signature verification is performed and the destination hosts have no relationship to the declared package purpose. The behavior fires purely from `require()` of the package.\n","modified":"2026-08-05T15:52:25.579620892Z","published":"2026-08-05T14:23:22Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015282","import_time":"2026-08-05T15:19:42.381933893Z","modified_time":"2026-08-05T14:23:22Z","sha256":"d880fad0158970d8ef9b0a0884fe6b2ceee572d3046db4cf08745d02d3c34293","source":"amazon-inspector","versions":["35.6.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bpm-foundation-base-configs/v/35.6.2"}],"affected":[{"package":{"name":"bpm-foundation-base-configs","ecosystem":"npm","purl":"pkg:npm/bpm-foundation-base-configs"},"versions":["35.6.2"],"database_specific":{"indicators":{"package_integrity":[{"filename":"bpm-foundation-base-configs-35.6.2.tgz","hashes":{"sha1":"eef300f3951ea970f651b1133a222f48405fb21f","sha512_sri":"sha512-lbIreQiML3fP9Wba3l18tuMqlBwVlvLFbGYOWy4qcvawhIPvPlk1R9ku2+XY4ZVUGG6ST4r8mDddzSmu14x/Tw=="}}],"evidence_files":[{"sha256":"d2a32b90fa53b21bb006f3010f27a107b4d292d897d66d2b8d45ed5183df87a9","tlsh":"c2a1a75a066a70198bb097e487274816f55bf76333c0c294f79ca9985fb60244372dfc","path":"_helpers.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bpm-foundation-base-configs/MAL-2026-13105.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}