-= Per source details. Do not edit below this line.=-
On any require()/import of bpm-foundation-rate-us, index.js loads compat.js, which assembles hostnames from split string fragments to hide the destinations oob-worker.cf<NNN>-<XXX>.workers.dev and, on HTTPS failure, falls back to reconstructing a base64 payload from DNS TXT records at sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The retrieved binary is written under a disguised name (dotnetdiag<rand>.exe on Windows,.cache<rand> on POSIX) to %TEMP%/ /tmp, chmod 0755'd on POSIX, and spawned detached via /bin/sh or cmd.exe. A freshness marker at /tmp/.analytics_state and cover-story telemetry comments frame the behavior as analytics. The package name suggests a rate-adapter utility, which is inconsistent with fetching and executing an opaque native binary from Cloudflare Workers subdomains and DNS TXT channels.
{
"malicious-packages-origins": [
{
"versions": [
"35.3.9"
],
"id": "IN-MAL-2026-015263",
"import_time": "2026-08-05T15:19:41.370446789Z",
"modified_time": "2026-08-05T14:20:29Z",
"source": "amazon-inspector",
"sha256": "14633165714201c44b540cc6b04a1f9bd6c311e27ec921e3c0011d6696120d54"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"filename": "bpm-foundation-rate-us-35.3.9.tgz",
"hashes": {
"sha512_sri": "sha512-IIx1LqpCd/O/1lTRtSUsnWk3H4UQvQFeBGYCz/p6qGa9Clt8U5Eh1nBhAjcvmAs/wvV3iG44vHsqKmK7+RZMAg==",
"sha1": "a018642a30134ee7e0c048e3e43c2d405f73fe42"
}
}
],
"evidence_files": [
{
"path": "_compat.js",
"tlsh": "e7b1869616aa31194b70dbe4cb274415f55bf6633780c5c8fbaca5981f7212482f2efc",
"sha256": "b1d4b2020fe5fb26a143cde50c6e79b87cb489c6e48919ac3e162fefc54eea47"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bpm-foundation-rate-us/MAL-2026-13115.json"