-= Per source details. Do not edit below this line.=-
On require() of the package, index.js loads runtime.js which selects a per-platform payload path, fetches an opaque binary over HTTPS from one of three Cloudflare Workers subdomains (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev) whose hostnames are assembled at runtime by joining fragmented string pieces to evade static analysis. When HTTPS delivery fails, a DNS-TXT covert channel reassembles a base64-encoded payload from numbered TXT records under *.dl.wel1.ru subdomains (also string-fragmented). The retrieved bytes are written to /var/tmp/.cache<rand> on POSIX or %TEMP%\dotnetdiag<rand>.exe on Windows (a decoy resembling a legitimate.NET diagnostic tool), chmod 0755, and spawned detached via /bin/sh -c or cmd /c start /b. The package presents itself as a code-style enforcer; none of the fetched or executed content relates to that purpose.
{
"malicious-packages-origins": [
{
"versions": [
"35.3.9"
],
"id": "IN-MAL-2026-015266",
"import_time": "2026-08-05T15:19:41.482684424Z",
"modified_time": "2026-08-05T14:21:00Z",
"source": "amazon-inspector",
"sha256": "b7753fe48a070f467d11a5dfef041b6919ff9914df1484d0ef0e59c95f583961"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bpm-foundation-linters/MAL-2026-13112.json"
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-4Q/0LV6rXXrol3/W8AWVszDpUEbyvmfSBbili7h4Xn4KV6cpp4FfC7kxUVBaXzCaAUvnh2AeWeMWje5+soJITA==",
"sha1": "a499ec58c1f56b7fc79a89f6845922d166207587"
},
"filename": "bpm-foundation-linters-35.3.9.tgz"
}
],
"evidence_files": [
{
"path": "_runtime.js",
"tlsh": "43a17596126670184bb0e7f4c61b8829f61af6633780c294fb9c65945f7312483b1efc",
"sha256": "6aaebb2c437ad8dcedd997a1837081199158bbd7d7e66c9f52d8c1cd0033e8ed"
}
]
}