-= Per source details. Do not edit below this line.=-
The package presents itself as an ESLint config / 'environment config reader' but on require() executes an import-time dropper. index.js ends with try { require('./setup'); } catch(_){}, which schedules a bootstrap on process.nextTick. setup.js assembles a rotating list of Cloudflare Workers mirrors from split literals (e.g. ["package-proxy.cf5oob","wor","ker.","wor","kers",".dev"], and cf8/cf12/cf17/cf25 siblings), plus a *.dl.well1.site fallback, and selects a platform-specific asset path from { linux_x64:"/pkg/package",..., darwin_arm64:"/pkg/package-arm64", darwin:"/pkg/loader_mac", win32:"/pkg/package.exe" }. lib/telemetry.js fetches the response, base64-decodes it (Buffer.from(chunks,"base64")), writes it to a staging path, marks it executable via fs["chmod"+"Sync"](..., 0o755), and executes it via require("child_"+"process"). Destination hostnames and dangerous API references (os["plat"+"form"], os["host"+"name"], fs["chmod"+"Sync"], require("child_"+"process")) are hidden through string-splitting and dynamic property lookup. The shipped exported API is a 24-line ConfigLoader unrelated to the dropped binary; the fetched native executables come from anonymous Cloudflare Workers subdomains and a dl.well1.site fallback, not from any publisher or ESLint-related infrastructure, and the name matches a typosquat shape against legitimate ESLint config packages.
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T01:48:00Z",
"sha256": "121c404b778f379999022d0b92e68ae7e8fd2663d1731b03af8e87cad3037676",
"id": "IN-MAL-2026-011530",
"versions": [
"12.5.7"
],
"import_time": "2026-08-05T03:11:17.976526728Z"
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T01:47:41Z",
"sha256": "30f16ba2b7357ecd393b34c006561c8642786667af55222b928b3b003f6c17ed",
"id": "IN-MAL-2026-011528",
"versions": [
"9.5.7"
],
"import_time": "2026-08-05T03:11:17.769340553Z"
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T01:48:08Z",
"sha256": "3bae1e6300947d81c5442b4931ad570867c66bc9ddbb04888a875a0b3e33e636",
"id": "IN-MAL-2026-011531",
"versions": [
"9.5.9"
],
"import_time": "2026-08-05T03:11:18.070690455Z"
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T01:47:53Z",
"sha256": "cea299913e6482aa04435c1a0b13864466ac9a96a6d74d87dacd6d2dfc731386",
"id": "IN-MAL-2026-011529",
"versions": [
"9.5.8"
],
"import_time": "2026-08-05T03:11:17.855977831Z"
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T01:48:15Z",
"sha256": "fe55f411284226c68e60cbcae266a390a3ba0ef089a2a709363df3188130f605",
"id": "IN-MAL-2026-011532",
"versions": [
"9.5.6"
],
"import_time": "2026-08-05T03:11:18.16827127Z"
}
]
}[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-X7zIH7GfdpjPgdQqxwrNk4ZpEUjA4vY8bG2dzClN8CULZCzdl1w/1UbqQgNE3YuQPB0g7W+CFe9TiTX4nR6AnQ==",
"sha1": "de2cda800ae79ebf492b1c73e5672c41c99e1cd1"
},
"filename": "bcore-bravo-eslint-config-12.5.7.tgz"
}
],
"evidence_files": [
{
"path": "setup.js",
"sha256": "8f0408a8a36dac6c84b61ce497abe4e97fbec7aa75120b387894e005dff29ac7",
"tlsh": "17b1a4550afa71384392a1e8d92b5816b09fe5533284e990f34cb6985f97268c3b39fc"
},
{
"path": "index.js",
"sha256": "a4b1c1434cade6ae9ec65ba276e9a4c53bccdeaa620f403b043565db588183ea",
"tlsh": "6e11b1a097caf6d386b067d28d2a0413fd5bc9262244929874dcb0de3f6942041a3ff8"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bcore-bravo-eslint-config/MAL-2026-12059.json"