{"id":"MAL-2026-12883","summary":"Malicious code in bnpl-blocks-atom-bnpl-no-index-link (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (02bfd5111a000f3f369e2f973d3717b22e1718fb2edbc4b38a07b67aa395815b)\nOn require of the package, index.js loads _bootstrap.js which detects OS and architecture, then fetches an OS-specific binary from string-split-obfuscated *.workers.dev endpoints (oob-worker.cf101-adf.workers.dev, cf103-070, cf99-9b3, cf100-416) with a DNS-TXT covert channel fallback that reassembles base64 chunks from numbered subdomains of sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The downloaded bytes are written to /var/tmp or %TEMP% under a disguised name (dotnet_diag_\u003crand\u003e.exe on Windows,.cache_\u003crand\u003e on Unix), chmod 0755, and spawned detached via /bin/sh or cmd. There is no hash or signature verification, and the destinations are not the publisher's infrastructure. The behavior is framed with cover-story naming (.analytics_state flag file, DISABLE_TELEMETRY/DO_NOT_TRACK/ANALYTICS_OPT_OUT env gates, dotnet_diag disguise) unrelated to the package's advertised 'bnpl blocks' purpose. Endpoints are assembled at runtime via array-join to evade static inspection.\n","modified":"2026-08-05T15:50:41.281946769Z","published":"2026-08-05T14:55:58Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T15:19:54.834901065Z","modified_time":"2026-08-05T14:55:58Z","sha256":"02bfd5111a000f3f369e2f973d3717b22e1718fb2edbc4b38a07b67aa395815b","source":"amazon-inspector","versions":["35.1.2"],"id":"IN-MAL-2026-015501"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-atom-bnpl-no-index-link/v/35.1.2"}],"affected":[{"package":{"name":"bnpl-blocks-atom-bnpl-no-index-link","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-atom-bnpl-no-index-link"},"versions":["35.1.2"],"database_specific":{"indicators":{"package_integrity":[{"filename":"bnpl-blocks-atom-bnpl-no-index-link-35.1.2.tgz","hashes":{"sha1":"9fb42caad27084b773588fcf948be6a8b3f0d5c7","sha512_sri":"sha512-0A/JeJS5DNBHNZXxXvLMvXCkIYvXizYuHfRAYkTCldsKfTbCcmW9LsTaAcPa2Wz9udFte3dzj3exwKfYzdVdKw=="}}],"evidence_files":[{"tlsh":"6ca1a75a15a6701987b0dbe486174816f65ffa633780c1c8fb9ca9984f76124c2b2efc","path":"_bootstrap.js","sha256":"ce0af129fd77384aeac3318942967732f4ad18e2fe2ffac0fa76252d650f8ea5"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-atom-bnpl-no-index-link/MAL-2026-12883.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}