MAL-2026-13117
Dashboard / Malicious Package / MAL-2026-13117
MAL-2026-13117
Summary: Malicious code in bpm-foundation-sentry (npm)
Details: Source: amazon-inspector (896fd9239310d1f672d716bb70e9720d15f59139fcc59ce6a935be7a60112001) The package's main entry (index.js) unconditionally requires _runtime.js, which downloads an opaque platform-specific binary at load time from hardcoded Cloudflare Workers subdomains (oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS-TXT base64 fallback under sdk.dl.wel1.ru, writes it to /var/tmp or %TEMP% under disguised names (.cache_<hex>, dotnet_diag_<hex>.exe,.analytics_state), sets mode 0755, and detached-spawns it via /bin/sh -c or cmd.exe /c start /b. C2 hostnames, the child_process import, and fs.chmodSync are assembled from split-string arrays and concatenation to evade string scanners. Cover-story naming and opt-out env checks present the behavior as telemetry, but the fetched bytes are opaque native code from anonymous *.workers.dev hosts unrelated to any declared publisher.
Affected packages
Package
Name: bpm-foundation-sentry
Purl: pkg:npm/bpm-foundation-sentry
Affected ranges
Type: N/A
Events:
