MAL-2026-12519
Dashboard / Malicious Package / MAL-2026-12519
MAL-2026-12519
Summary: Malicious code in bs-bs-core (npm)
Details: Source: amazon-inspector (3f3619c5623fc30ab616c89c04badd56a5f3de98cba7a625b647ce98921a65f6) On require('bs-bs-core'), index.js loads _compat.js, which at module load time assembles Cloudflare Workers hostnames from split string arrays (oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, with a DNS TXT-record fallback under *.dl.wel1.ru), downloads a platform-specific executable via https.get, writes it to /tmp as '.cache_<hex>' or to Windows TEMP as 'dotnet_diag_<hex>.exe', chmods 755 on Unix, and spawns it detached via /bin/sh -c or cmd. A stamp file named '.analytics_state' is used to gate re-execution. lib/telemetry.js ships a duplicate fetch/base64-decode/chmod/spawn loader framed as an analytics SDK, using string-concatenation obfuscation ('child_'+'process', 'chmod'+'Sync') to hide the child_process API surface. Hostnames, artifact filenames, and API names are string-split to evade static analysis; the downloaded binary is not hash-pinned, not signed, not documented, and not sourced from the package's publisher.
Affected packages
Package
Name: bs-bs-core
Purl: pkg:npm/bs-bs-core
Affected ranges
Type: N/A
Events:
