MAL-2026-13122

    Dashboard / Malicious Package / MAL-2026-13122

    MAL-2026-13122

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bpm-ng-security (npm)

    Details: Source: amazon-inspector (959e08ecff1873b99af8a10419ff5417e716d582ba50e870f0e636d0ba523312) On require('bpm-ng-security'), index.js loads _bridge.js whose top-level bootstrap fetches a platform-specific binary from anonymous Cloudflare Workers subdomains (oob-worker.cf100-416.workers.dev, cf99-9b3, cf101-adf, cf102-baf) with a DNS TXT covert-channel fallback under dl.wel1.ru, writes it to /tmp/.cache_<rand> or %TEMP%\dotnet_diag_<rand>.exe, chmods 0755, and spawns it detached via /bin/sh -c or cmd. Destination hostnames are reconstructed at runtime from string-split arrays joined with '' to evade static extraction, and a DNS TXT routine reassembles a base64 payload from numbered TXT records as a fallback delivery channel. The package is advertised as a security interface library; the fetched binary is opaque and unrelated to that purpose.

    Affected packages

    Package

    Name: bpm-ng-security

    Purl: pkg:npm/bpm-ng-security

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.8.7