{"id":"MAL-2026-13115","summary":"Malicious code in bpm-foundation-rate-us (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (14633165714201c44b540cc6b04a1f9bd6c311e27ec921e3c0011d6696120d54)\nOn any require()/import of bpm-foundation-rate-us, index.js loads _compat.js, which assembles hostnames from split string fragments to hide the destinations oob-worker.cf\u003cNNN\u003e-\u003cXXX\u003e.workers.dev and, on HTTPS failure, falls back to reconstructing a base64 payload from DNS TXT records at sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The retrieved binary is written under a disguised name (dotnet_diag_\u003crand\u003e.exe on Windows,.cache_\u003crand\u003e on POSIX) to %TEMP%/ /tmp, chmod 0755'd on POSIX, and spawned detached via /bin/sh or cmd.exe. A freshness marker at /tmp/.analytics_state and cover-story telemetry comments frame the behavior as analytics. The package name suggests a rate-adapter utility, which is inconsistent with fetching and executing an opaque native binary from Cloudflare Workers subdomains and DNS TXT channels.\n","modified":"2026-08-05T15:52:30.650655562Z","published":"2026-08-05T14:20:29Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T15:19:41.370446789Z","modified_time":"2026-08-05T14:20:29Z","sha256":"14633165714201c44b540cc6b04a1f9bd6c311e27ec921e3c0011d6696120d54","source":"amazon-inspector","versions":["35.3.9"],"id":"IN-MAL-2026-015263"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bpm-foundation-rate-us/v/35.3.9"}],"affected":[{"package":{"name":"bpm-foundation-rate-us","ecosystem":"npm","purl":"pkg:npm/bpm-foundation-rate-us"},"versions":["35.3.9"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha1":"a018642a30134ee7e0c048e3e43c2d405f73fe42","sha512_sri":"sha512-IIx1LqpCd/O/1lTRtSUsnWk3H4UQvQFeBGYCz/p6qGa9Clt8U5Eh1nBhAjcvmAs/wvV3iG44vHsqKmK7+RZMAg=="},"filename":"bpm-foundation-rate-us-35.3.9.tgz"}],"evidence_files":[{"sha256":"b1d4b2020fe5fb26a143cde50c6e79b87cb489c6e48919ac3e162fefc54eea47","tlsh":"e7b1869616aa31194b70dbe4cb274415f55bf6633780c5c8fbaca5981f7212482f2efc","path":"_compat.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bpm-foundation-rate-us/MAL-2026-13115.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}