{"id":"MAL-2026-12915","summary":"Malicious code in bnpl-blocks-desktop-bnpl-button-set (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e7581057c70b3b5e805e0d56c30e74c4fc88c8c23aa0ceb73a46a2b17b937bb0)\nOn require of the package, index.js loads _polyfill.js which selects a platform-specific asset, fetches a binary from string-fragmented Cloudflare Workers hostnames (e.g. oob-worker.cf102-baf.workers.dev, assembled at runtime via array.join('') to evade static scanners) with a DNS-TXT base64 reassembly fallback via *.dl.wel1.ru, writes the payload to /tmp or %TEMP% under disguised names such as '.cache_\u003crand\u003e' or 'dotnet_diag_\u003crand\u003e.exe', chmods it 0755, and spawns it detached via /bin/sh -c '\u003cpath\u003e &' (or cmd on Windows). A filesystem stamp at /tmp/.analytics_state throttles re-runs. The destinations are not first-party, not pinned, and the fetched bytes are unverified. A parallel, currently-unreferenced dropper module lib/telemetry.js ships the same scaffolding (child_process spawn of /bin/sh, base64 chunk assembly, chmod 0755) bundled in the tarball. The package advertises a UI (BNPL button set) adapter, which is inconsistent with fetching and executing remote native binaries on require.\n","modified":"2026-08-05T15:50:56.198179921Z","published":"2026-08-05T14:51:32Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T14:51:32Z","sha256":"e7581057c70b3b5e805e0d56c30e74c4fc88c8c23aa0ceb73a46a2b17b937bb0","source":"amazon-inspector","versions":["35.3.7"],"id":"IN-MAL-2026-015470","import_time":"2026-08-05T15:19:53.178116546Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-desktop-bnpl-button-set/v/35.3.7"}],"affected":[{"package":{"name":"bnpl-blocks-desktop-bnpl-button-set","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-desktop-bnpl-button-set"},"versions":["35.3.7"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"bnpl-blocks-desktop-bnpl-button-set-35.3.7.tgz","hashes":{"sha1":"f2fa1cc027aa14b10a730b3be39d2d8f6a9c153a","sha512_sri":"sha512-wECpWVQ3KUyCUIsl8jSZebzT0DszlXQkLgAurFRMMB+PU1Lr0sVs6glt7nL9dG6T4NZ6z93IqRBAtjVGUHu67A=="}}],"evidence_files":[{"path":"_polyfill.js","sha256":"629066f957b2cbba7c74b4336192154b73888bb3922ddb0ccab73182be2a5274","tlsh":"f7a1975a06b630198bb0dbe4cb174816f65ae6633780c684fb9ca9945f73524c3b2dfc"},{"path":"lib/telemetry.js","sha256":"0bc17a1413a411eac451211ae760f47af43a6894ec5447ac11c788492582b212","tlsh":"c9835055566a242186b2b378df234107ff3685272642429dbafc82dc1fbd72092a5ffc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-desktop-bnpl-button-set/MAL-2026-12915.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}