LWA-2026-7320 MAL-2026-12059 ↗ confirmed malware

bcore-bravo-eslint-config@9.5.7

Malicious code in bcore-bravo-eslint-config (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1204.002 · Malicious File

Analysis

bcore-bravo-eslint-config is a combosquat package that downloads and executes a native binary on require(). On import, it collects a host fingerprint (hostname, username, cwd, Node.js version, PID) and contacts C2 servers at oob-worker[.]cf (subdomains: 99-9b3, 100-416, 101-adf, 102-baf, 103-070) and well1[.]site (subdomains: tin.dl, tina.dl, ldr.dl, win.dl) to download a platform-specific binary. The binary is written to /var/tmp (or %TEMP% on Windows) and executed as a detached process with output discarded. The package has no repository URL and its name impersonates an ESLint configuration package.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 11:16 AM
analyzed
Aug 1, 2026, 11:20 AM
weekly installs
113

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.