{"id":"MAL-2026-12869","summary":"Malicious code in bnpl-blocks-atom-bnpl-carousel-line (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f49d0a2f45c6a825ed105c2859c618bedcc4643650bf6719c35c47e462c553c8)\nOn require of the package's main entry, index.js loads./_shim.js, which assembles attacker-controlled hostnames from string-split arrays (e.g. [\"oob-work\",\"er.cf101-adf.w\",\"orke\",\"rs.d\",\"ev\"].join(\"\") and [\"sdk.\",\"dl.we\",\"l1.\",\"ru\"].join(\"\")), downloads a platform-specific binary over HTTPS from a rotated list of oob-worker.cf10*-*.workers.dev hosts with a DNS TXT fallback under dl.wel1.ru, writes it to /var/tmp/.cache_\u003crnd\u003e on Unix or %TEMP%\\dotnet_diag_\u003crnd\u003e.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start. A sibling file lib/telemetry.js contains the same fetch-decode-chmod-exec pattern with dynamic property construction (fs[\"chmod\"+\"Sync\"]) disguised as an analytics SDK. The package name suggests a BNPL UI component but ships an install/import-time binary dropper with hostname obfuscation and DNS-over-TXT fallback for HTTPS blocking.\n","modified":"2026-08-05T15:50:34.151688575Z","published":"2026-08-05T14:57:22Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015510","import_time":"2026-08-05T15:19:55.373723294Z","modified_time":"2026-08-05T14:57:22Z","sha256":"f49d0a2f45c6a825ed105c2859c618bedcc4643650bf6719c35c47e462c553c8","source":"amazon-inspector","versions":["35.1.6"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-atom-bnpl-carousel-line/v/35.1.6"}],"affected":[{"package":{"name":"bnpl-blocks-atom-bnpl-carousel-line","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-atom-bnpl-carousel-line"},"versions":["35.1.6"],"database_specific":{"indicators":{"evidence_files":[{"path":"_shim.js","sha256":"9c193de3839a900de9facd973fc42d833ec79ad97d2285637f3b9129be62867f","tlsh":"c4b1a66616a6701c8bb0dbe5c60b5415f65af6633380c2d4fb9c69985ff312482b2efc"},{"sha256":"aa19fb0f90e19318fdafe9730cc24d53cde3646b5da85196524064c3853eb2b1","tlsh":"35835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}],"package_integrity":[{"filename":"bnpl-blocks-atom-bnpl-carousel-line-35.1.6.tgz","hashes":{"sha1":"264c35e7a0e5dada4ff3e299cee586845a1c8e62","sha512_sri":"sha512-5Kk/pQRVq7R2+ku1yWi6y9ytwmSGnV+x8hATM4P3vK3WhvMSVMeYo5XDFxLLRbXhsIxtLtacN9f41y/r203KMA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-atom-bnpl-carousel-line/MAL-2026-12869.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}