MAL-2026-12517
Dashboard / Malicious Package / MAL-2026-12517
MAL-2026-12517
Summary: Malicious code in bpm-renovate-renovate-config (npm)
Details: Source: amazon-inspector (3b2fc5b92d1c0023e38459ab9285d928b6fbe3124bfda9d4d6b055dd1fe0bf4e) On require, index.js loads setup.js which downloads a platform-specific binary over HTTPS from one of four string-concatenation-obfuscated *.workers.dev hosts (oob-worker.cf100-416.workers.dev, cf101-adf.workers.dev, cf102-baf.workers.dev, cf99-9b3.workers.dev), with a DNS-TXT-record base64 fallback channel via subdomains of dl.wel1.ru. The fetched payload is written to /tmp or %TEMP% under decoy names (e.g. dotnet_diag_*.exe,.cache_*), chmod 0755 on Unix, and spawned detached via /bin/sh -c or cmd.exe. Hostnames are constructed by joining short substrings at runtime to evade static URL scanning. A companion module lib/telemetry.js contains the same fetch-decode-chmod-spawn pattern using property-name concatenation (fs['chmod'+'Sync'], require('child_'+'process')) and base64 buffer construction. This is a supply-chain dropper delivering arbitrary attacker-controlled native code to any host that installs or requires the package.
Affected packages
Package
Name: bpm-renovate-renovate-config
Purl: pkg:npm/bpm-renovate-renovate-config
Affected ranges
Type: N/A
Events:
