bcore-bravo-eslint-config@9.5.7
Malicious code in bcore-bravo-eslint-config (npm)
Analysis
bcore-bravo-eslint-config is a combosquat package that downloads and executes a native binary on require(). On import, it collects a host fingerprint (hostname, username, cwd, Node.js version, PID) and contacts C2 servers at oob-worker[.]cf (subdomains: 99-9b3, 100-416, 101-adf, 102-baf, 103-070) and well1[.]site (subdomains: tin.dl, tina.dl, ldr.dl, win.dl) to download a platform-specific binary. The binary is written to /var/tmp (or %TEMP% on Windows) and executed as a detached process with output discarded. The package has no repository URL and its name impersonates an ESLint configuration package.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 11:16 AM
- analyzed
- Aug 1, 2026, 11:20 AM
- weekly installs
- 113
Related advisories
- accounts-timeline@9.6.10
- a.poltoradnev-package-c@6.1.10
- warp-drive-internal-tooling@99.9.9
- mcp-audit-sync-internal@99.9.9
- native-hello-plugin@1.2.0
- streak-metric-core@1.0.0
- react-fast-refresh-helper@1.2.6
- express-middle@5.5.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.