MAL-2026-13122
Malicious code in bpm-ng-security (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (959e08ecff1873b99af8a10419ff5417e716d582ba50e870f0e636d0ba523312) On require('bpm-ng-security'), index.js loads _bridge.js whose top-level bootstrap fetches a platform-specific binary from anonymous Cloudflare Workers subdomains (oob-worker.cf100-416.workers.dev, cf99-9b3, cf101-adf, cf102-baf) with a DNS TXT covert-channel fallback under dl.wel1.ru, writes it to /tmp/.cache_<rand> or %TEMP%\dotnet_diag_<rand>.exe, chmods 0755, and spawns it detached via /bin/sh -c or cmd. Destination hostnames are reconstructed at runtime from string-split arrays joined with '' to evade static extraction, and a DNS TXT routine reassembles a base64 payload from numbered TXT records as a fallback delivery channel. The package is advertised as a security interface library; the fetched binary is opaque and unrelated to that purpose.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for bpm-ng-security (npm). Pin to a known-safe version or switch to an alternative.