MAL-2026-12059

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bcore-bravo-eslint-config/MAL-2026-12059.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12059
Published
2026-08-05T01:47:41Z
Modified
2026-08-05T03:20:46.052035730Z
Summary
Malicious code in bcore-bravo-eslint-config (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (fe55f411284226c68e60cbcae266a390a3ba0ef089a2a709363df3188130f605)

The package presents itself as an ESLint config / 'environment config reader' but on require() executes an import-time dropper. index.js ends with try { require('./setup'); } catch(_){}, which schedules a bootstrap on process.nextTick. setup.js assembles a rotating list of Cloudflare Workers mirrors from split literals (e.g. ["package-proxy.cf5oob","wor","ker.","wor","kers",".dev"], and cf8/cf12/cf17/cf25 siblings), plus a *.dl.well1.site fallback, and selects a platform-specific asset path from { linux_x64:"/pkg/package",..., darwin_arm64:"/pkg/package-arm64", darwin:"/pkg/loader_mac", win32:"/pkg/package.exe" }. lib/telemetry.js fetches the response, base64-decodes it (Buffer.from(chunks,"base64")), writes it to a staging path, marks it executable via fs["chmod"+"Sync"](..., 0o755), and executes it via require("child_"+"process"). Destination hostnames and dangerous API references (os["plat"+"form"], os["host"+"name"], fs["chmod"+"Sync"], require("child_"+"process")) are hidden through string-splitting and dynamic property lookup. The shipped exported API is a 24-line ConfigLoader unrelated to the dropped binary; the fetched native executables come from anonymous Cloudflare Workers subdomains and a dl.well1.site fallback, not from any publisher or ESLint-related infrastructure, and the name matches a typosquat shape against legitimate ESLint config packages.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T01:48:00Z",
            "sha256": "121c404b778f379999022d0b92e68ae7e8fd2663d1731b03af8e87cad3037676",
            "id": "IN-MAL-2026-011530",
            "versions": [
                "12.5.7"
            ],
            "import_time": "2026-08-05T03:11:17.976526728Z"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T01:47:41Z",
            "sha256": "30f16ba2b7357ecd393b34c006561c8642786667af55222b928b3b003f6c17ed",
            "id": "IN-MAL-2026-011528",
            "versions": [
                "9.5.7"
            ],
            "import_time": "2026-08-05T03:11:17.769340553Z"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T01:48:08Z",
            "sha256": "3bae1e6300947d81c5442b4931ad570867c66bc9ddbb04888a875a0b3e33e636",
            "id": "IN-MAL-2026-011531",
            "versions": [
                "9.5.9"
            ],
            "import_time": "2026-08-05T03:11:18.070690455Z"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T01:47:53Z",
            "sha256": "cea299913e6482aa04435c1a0b13864466ac9a96a6d74d87dacd6d2dfc731386",
            "id": "IN-MAL-2026-011529",
            "versions": [
                "9.5.8"
            ],
            "import_time": "2026-08-05T03:11:17.855977831Z"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T01:48:15Z",
            "sha256": "fe55f411284226c68e60cbcae266a390a3ba0ef089a2a709363df3188130f605",
            "id": "IN-MAL-2026-011532",
            "versions": [
                "9.5.6"
            ],
            "import_time": "2026-08-05T03:11:18.16827127Z"
        }
    ]
}
References
Credits

Affected packages

npm / bcore-bravo-eslint-config

Package

Name
bcore-bravo-eslint-config
View open source insights on deps.dev
Purl
pkg:npm/bcore-bravo-eslint-config

Affected ranges

Affected versions

9.*
9.5.6
9.5.7
9.5.8
9.5.9
12.*
12.5.7

Database specific

cwes
[
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-X7zIH7GfdpjPgdQqxwrNk4ZpEUjA4vY8bG2dzClN8CULZCzdl1w/1UbqQgNE3YuQPB0g7W+CFe9TiTX4nR6AnQ==",
                "sha1": "de2cda800ae79ebf492b1c73e5672c41c99e1cd1"
            },
            "filename": "bcore-bravo-eslint-config-12.5.7.tgz"
        }
    ],
    "evidence_files": [
        {
            "path": "setup.js",
            "sha256": "8f0408a8a36dac6c84b61ce497abe4e97fbec7aa75120b387894e005dff29ac7",
            "tlsh": "17b1a4550afa71384392a1e8d92b5816b09fe5533284e990f34cb6985f97268c3b39fc"
        },
        {
            "path": "index.js",
            "sha256": "a4b1c1434cade6ae9ec65ba276e9a4c53bccdeaa620f403b043565db588183ea",
            "tlsh": "6e11b1a097caf6d386b067d28d2a0413fd5bc9262244929874dcb0de3f6942041a3ff8"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bcore-bravo-eslint-config/MAL-2026-12059.json"