{"id":"MAL-2026-13107","summary":"Malicious code in bpm-foundation-common (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (39a9ca2287ec8bbf000796cf1f41fbc088f7d8a3a37cd8d8eadc970cf19abc91)\nOn require('bpm-foundation-common'), index.js loads _loader.js which assembles C2 hostnames via runtime string-joining (e.g. [\"oob-worker.\",\"cf101-adf.\",\"workers.d\",\"ev\"].join(\"\")) with a DNS-TXT fallback to *.wel1.ru subdomains, downloads a platform-specific binary via https.get, writes it to /tmp/.cache_\u003chex\u003e or %TEMP%/dotnet_diag_\u003chex\u003e.exe, chmods 0755, and detached-spawns it via /bin/sh -c or cmd.exe. Dangerous API names are obfuscated (require(\"child_\"+\"process\"), fs[\"chmod\"+\"Sync\"]) to evade static analysis. A second dropper implementation with the same machinery (base64-decoded payload, /bin/sh -c spawn, chmod 0755) is bundled in lib/telemetry.js as an alternate payload path. The package has no documented native-build purpose that would justify fetching and executing a remote binary on require().\n","modified":"2026-08-05T15:52:26.002455378Z","published":"2026-08-05T14:22:16Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015274","import_time":"2026-08-05T15:19:41.991011515Z","modified_time":"2026-08-05T14:22:16Z","sha256":"39a9ca2287ec8bbf000796cf1f41fbc088f7d8a3a37cd8d8eadc970cf19abc91","source":"amazon-inspector","versions":["35.9.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bpm-foundation-common/v/35.9.1"}],"affected":[{"package":{"name":"bpm-foundation-common","ecosystem":"npm","purl":"pkg:npm/bpm-foundation-common"},"versions":["35.9.1"],"database_specific":{"indicators":{"evidence_files":[{"path":"_loader.js","sha256":"db5ae801a828d3c44f348080b619dea664b177986f50bdfa8693463832d69aa1","tlsh":"2ba1b7aa116a71084b70ebe4c7174415f65bf6633780c284fb6c55885fb6128c3b1efc"},{"sha256":"f4d98252df56571f530d52e14912dea2e6fc907cf4bea6853e5c537f7fd32f31","tlsh":"b0835055566a602186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}],"package_integrity":[{"filename":"bpm-foundation-common-35.9.1.tgz","hashes":{"sha512_sri":"sha512-pTHFz7RAamBjoGZkhXQqvTbzPpqZ9tpN2EUMiiXCZ1R7jatIC2rO440n7ZAtjx4l2VyyUtWe1hhz3FumyMMwOA==","sha1":"7cd2c89a58002517c902a2a795e7a455be9802fc"}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bpm-foundation-common/MAL-2026-13107.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}