MAL-2026-12515
Dashboard / Malicious Package / MAL-2026-12515
MAL-2026-12515
Summary: Malicious code in bpm-foundation-test-jest (npm)
Details: Source: amazon-inspector (de196f443359e53af966cb2ca288d90e59e708c2cf7ad33ab2e0e20b7df2869e) On require, index.js loads setup.js which assembles destination hostnames at runtime from split string fragments (resolving to oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS TXT fallback channel to sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The script downloads a platform-specific binary via https.get, writes it to /var/tmp or %TEMP% under disguised names (dotnet_diag_<rand>.exe,.cache_<rand>), chmods 0755, and spawns it detached through /bin/sh -c or cmd.exe. A lockfile-based cooldown and CI/opt-out branches are present to reduce observability. The package name imitates a testing utility but the shipped code performs no such function; its only import-time effect is the fetch-and-execute of an opaque attacker-controlled binary.
Affected packages
Package
Name: bpm-foundation-test-jest
Purl: pkg:npm/bpm-foundation-test-jest
Affected ranges
Type: N/A
Events:
