{"id":"MAL-2026-12912","summary":"Malicious code in bnpl-blocks-desktop-bnpl-anchor-title (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (67f1356b6c4fb134c3e3a35f562fe646d5db925c24354f286159be061213013c)\nOn `require()` of this package, `_bootstrap.js` downloads a platform-specific binary from author-controlled Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) and fallback hosts under dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), writes it to a temp path, sets it executable (chmod 0755), and spawns it detached via `/bin/sh -c` (with a `cmd` branch for Windows). The destination hostnames and API names are reassembled at runtime from split string fragments (e.g. [\"oob-wo\",\"rker.cf1\",\"01-adf\",\".wo\",\"rkers\",\".dev\"].join(\"\"), fs[\"chmod\"+\"Sync\"]) to evade literal-string scanning. The binary is fetched unpinned and unverified from non-publisher infrastructure; the package presents an analytics/telemetry cover story. `lib/telemetry.js` contains parallel dropper primitives (base64-chunked reassembly, chmod-to-755, detached /bin/sh spawn) as a staged variant.\n","modified":"2026-08-05T15:50:54.875301372Z","published":"2026-08-05T14:50:35Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T15:19:52.832057715Z","modified_time":"2026-08-05T14:50:35Z","sha256":"67f1356b6c4fb134c3e3a35f562fe646d5db925c24354f286159be061213013c","source":"amazon-inspector","versions":["35.2.5"],"id":"IN-MAL-2026-015463"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-desktop-bnpl-anchor-title/v/35.2.5"}],"affected":[{"package":{"name":"bnpl-blocks-desktop-bnpl-anchor-title","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-desktop-bnpl-anchor-title"},"versions":["35.2.5"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"39de669e0c6ab0694782afeafb308a6debf42a16","sha512_sri":"sha512-ROEEG2f150rcSRrT16EAPxls5B88gXWx7gIhF7nKuLiLflsd6RHoXr4dnfAsDNF4QNCdBWJgjvWV94A+/nMhFA=="},"filename":"bnpl-blocks-desktop-bnpl-anchor-title-35.2.5.tgz"}],"evidence_files":[{"path":"_bootstrap.js","sha256":"3ee05aee6578c010a2287e2bed22f886b72d7d5910caaffa2b562dac674338d5","tlsh":"43a1979a16aa30094bb0d7e5c71b4416f69bf66333809288fb9c65941f7343483b2efc"},{"tlsh":"26835055566a602186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js","sha256":"fe05676e068db56bd7e7a7667b45574782b135162a4d754f8c89193971684f98"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-desktop-bnpl-anchor-title/MAL-2026-12912.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}