{"id":"MAL-2026-12903","summary":"Malicious code in bnpl-blocks-atom-desktop-bnpl-text (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (007bafa1def88d10e8f2c247e0ab1d0872d2a4f33f4bb134fe46877f75aa9eca)\nOn require(), index.js unconditionally loads _polyfill.js, which selects a platform-specific asset path and fetches an opaque binary from one of three Cloudflare Workers hostnames (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), with a DNS-TXT fallback resolving subdomains of wel1.ru. The C2 hostnames are assembled at runtime from split string fragments joined with.join('') to evade literal string matching. The fetched bytes are written to /var/tmp or %TEMP% under a disguised name (`.cache_\u003chex\u003e` on POSIX, `dotnet_diag_\u003chex\u003e.exe` on Windows) mimicking a.NET diagnostic tool, chmod'd to 0755, and spawned detached via `/bin/sh -c '\u003cpath\u003e &'` or `cmd`. Execution is gated by a stamp file and environment opt-outs to reduce observability. The package advertises a trivial text-abstraction layer with no legitimate need for a native binary or platform-specific asset delivery.\n","modified":"2026-08-05T15:50:50.596972Z","published":"2026-08-05T14:54:07Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T15:19:54.003892676Z","modified_time":"2026-08-05T14:54:07Z","sha256":"007bafa1def88d10e8f2c247e0ab1d0872d2a4f33f4bb134fe46877f75aa9eca","source":"amazon-inspector","versions":["35.2.5"],"id":"IN-MAL-2026-015488"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-atom-desktop-bnpl-text/v/35.2.5"}],"affected":[{"package":{"name":"bnpl-blocks-atom-desktop-bnpl-text","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-atom-desktop-bnpl-text"},"versions":["35.2.5"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"bee20262361ef34851a0ee7438367339f837d75a","sha512_sri":"sha512-GeYdM8Wy09wsL1YNKloWQO7F3f916+PzRF68IYzxHqKFcrLh75y8Nxl96kz1AHGb57ZEJqZnYROg+HDJl2aDEg=="},"filename":"bnpl-blocks-atom-desktop-bnpl-text-35.2.5.tgz"}],"evidence_files":[{"path":"_polyfill.js","sha256":"6fff8dd186476fe1d043f32ac7c48405a95d4a78dde15c6a09a679a802e4fa9a","tlsh":"7aa1a75a16b570198bb097e0c71b4416f55bf6633780d294fb9ce5981fb60248372efc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-atom-desktop-bnpl-text/MAL-2026-12903.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}