{"id":"MAL-2026-13112","summary":"Malicious code in bpm-foundation-linters (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b7753fe48a070f467d11a5dfef041b6919ff9914df1484d0ef0e59c95f583961)\nOn require() of the package, index.js loads _runtime.js which selects a per-platform payload path, fetches an opaque binary over HTTPS from one of three Cloudflare Workers subdomains (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev) whose hostnames are assembled at runtime by joining fragmented string pieces to evade static analysis. When HTTPS delivery fails, a DNS-TXT covert channel reassembles a base64-encoded payload from numbered TXT records under *.dl.wel1.ru subdomains (also string-fragmented). The retrieved bytes are written to /var/tmp/.cache_\u003crand\u003e on POSIX or %TEMP%\\dotnet_diag_\u003crand\u003e.exe on Windows (a decoy resembling a legitimate.NET diagnostic tool), chmod 0755, and spawned detached via /bin/sh -c or cmd /c start /b. The package presents itself as a code-style enforcer; none of the fetched or executed content relates to that purpose.\n","modified":"2026-08-05T15:52:29.384527094Z","published":"2026-08-05T14:21:00Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.3.9"],"id":"IN-MAL-2026-015266","import_time":"2026-08-05T15:19:41.482684424Z","modified_time":"2026-08-05T14:21:00Z","sha256":"b7753fe48a070f467d11a5dfef041b6919ff9914df1484d0ef0e59c95f583961"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bpm-foundation-linters/v/35.3.9"}],"affected":[{"package":{"name":"bpm-foundation-linters","ecosystem":"npm","purl":"pkg:npm/bpm-foundation-linters"},"versions":["35.3.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bpm-foundation-linters/MAL-2026-13112.json","indicators":{"evidence_files":[{"tlsh":"43a17596126670184bb0e7f4c61b8829f61af6633780c294fb9c65945f7312483b1efc","path":"_runtime.js","sha256":"6aaebb2c437ad8dcedd997a1837081199158bbd7d7e66c9f52d8c1cd0033e8ed"}],"package_integrity":[{"hashes":{"sha1":"a499ec58c1f56b7fc79a89f6845922d166207587","sha512_sri":"sha512-4Q/0LV6rXXrol3/W8AWVszDpUEbyvmfSBbili7h4Xn4KV6cpp4FfC7kxUVBaXzCaAUvnh2AeWeMWje5+soJITA=="},"filename":"bpm-foundation-linters-35.3.9.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}