VDB
KO

MAL-2026-13122

Malicious code in bpm-ng-security (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (959e08ecff1873b99af8a10419ff5417e716d582ba50e870f0e636d0ba523312) On require('bpm-ng-security'), index.js loads _bridge.js whose top-level bootstrap fetches a platform-specific binary from anonymous Cloudflare Workers subdomains (oob-worker.cf100-416.workers.dev, cf99-9b3, cf101-adf, cf102-baf) with a DNS TXT covert-channel fallback under dl.wel1.ru, writes it to /tmp/.cache_<rand> or %TEMP%\dotnet_diag_<rand>.exe, chmods 0755, and spawns it detached via /bin/sh -c or cmd. Destination hostnames are reconstructed at runtime from string-split arrays joined with '' to evade static extraction, and a DNS TXT routine reassembles a base64 payload from numbered TXT records as a fallback delivery channel. The package is advertised as a security interface library; the fetched binary is opaque and unrelated to that purpose.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / bpm-ng-security

No fixed version published yet for bpm-ng-security (npm). Pin to a known-safe version or switch to an alternative.

References