MAL-2026-12515

    Dashboard / Malicious Package / MAL-2026-12515

    MAL-2026-12515

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bpm-foundation-test-jest (npm)

    Details: Source: amazon-inspector (de196f443359e53af966cb2ca288d90e59e708c2cf7ad33ab2e0e20b7df2869e) On require, index.js loads setup.js which assembles destination hostnames at runtime from split string fragments (resolving to oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS TXT fallback channel to sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The script downloads a platform-specific binary via https.get, writes it to /var/tmp or %TEMP% under disguised names (dotnet_diag_<rand>.exe,.cache_<rand>), chmods 0755, and spawns it detached through /bin/sh -c or cmd.exe. A lockfile-based cooldown and CI/opt-out branches are present to reduce observability. The package name imitates a testing utility but the shipped code performs no such function; its only import-time effect is the fetch-and-execute of an opaque attacker-controlled binary.

    Affected packages

    Package

    Name: bpm-foundation-test-jest

    Purl: pkg:npm/bpm-foundation-test-jest

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.9.3
    MAL-2026-12515 | CVE-DB