Malicious code in bs-bs-core (npm)
The npm package bs-bs-core version 35.1.6 contains malicious code that downloads and executes a platform-specific binary from obfuscated Cloudflare Workers hostnames. This binary is saved to temporary directories and executed detached from the main process. The package also includes an obfuscated analytics SDK loader that uses child process APIs to spawn the binary. The downloaded executable is unsigned, not hash-verified, and not sourced from the package publisher, indicating a supply chain compromise or malicious intent.
AI Analysis
Technical Summary
The bs-bs-core npm package at version 35.1.6 includes malicious functionality where, upon requiring the module, it dynamically constructs Cloudflare Workers hostnames and attempts to download a platform-specific executable via HTTPS. This executable is saved in temporary directories with randomized filenames, permissions are set to executable, and it is spawned detached using shell commands. The package uses string concatenation and splitting to obfuscate critical API calls such as child_process spawning and chmod operations to evade static analysis. The downloaded binary lacks signature verification or hash pinning and is not officially documented or published by the package maintainer, strongly indicating malicious code execution embedded within the package.
Potential Impact
Users who install and require bs-bs-core version 35.1.6 risk automatic download and execution of an unknown and unsigned binary on their systems. This can lead to unauthorized code execution, potential system compromise, and persistence via a stamped file gating re-execution. The obfuscation and lack of verification increase the risk of undetected malicious activity and supply chain compromise.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid using bs-bs-core version 35.1.6 and remove it from their environments. Investigate any systems where this package was installed for signs of compromise. Monitor for updates or advisories from the package publisher or security vendors. Since no patch is confirmed, users must rely on removal and avoidance until an official fix or advisory is released.
Malicious code in bs-bs-core (npm)
Description
The npm package bs-bs-core version 35.1.6 contains malicious code that downloads and executes a platform-specific binary from obfuscated Cloudflare Workers hostnames. This binary is saved to temporary directories and executed detached from the main process. The package also includes an obfuscated analytics SDK loader that uses child process APIs to spawn the binary. The downloaded executable is unsigned, not hash-verified, and not sourced from the package publisher, indicating a supply chain compromise or malicious intent.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The bs-bs-core npm package at version 35.1.6 includes malicious functionality where, upon requiring the module, it dynamically constructs Cloudflare Workers hostnames and attempts to download a platform-specific executable via HTTPS. This executable is saved in temporary directories with randomized filenames, permissions are set to executable, and it is spawned detached using shell commands. The package uses string concatenation and splitting to obfuscate critical API calls such as child_process spawning and chmod operations to evade static analysis. The downloaded binary lacks signature verification or hash pinning and is not officially documented or published by the package maintainer, strongly indicating malicious code execution embedded within the package.
Potential Impact
Users who install and require bs-bs-core version 35.1.6 risk automatic download and execution of an unknown and unsigned binary on their systems. This can lead to unauthorized code execution, potential system compromise, and persistence via a stamped file gating re-execution. The obfuscation and lack of verification increase the risk of undetected malicious activity and supply chain compromise.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid using bs-bs-core version 35.1.6 and remove it from their environments. Investigate any systems where this package was installed for signs of compromise. Monitor for updates or advisories from the package publisher or security vendors. Since no patch is confirmed, users must rely on removal and avoidance until an official fix or advisory is released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12519
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735731bf8831d53913cf4e
Added to database: 08/05/2026, 15:30:57 UTC
Last enriched: 08/05/2026, 15:45:48 UTC
Last updated: 08/05/2026, 15:45:48 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.