{"id":"MAL-2026-12919","summary":"Malicious code in bnpl-blocks-desktop-bnpl-container (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c8ebc784cdc9c083f42cf6323e773eb7bf43b1b927c936c609bb8d93a90bb4cb)\nOn any require()/import of this package, index.js loads _ext.js which downloads a platform-specific binary over HTTPS from string-split-obfuscated Cloudflare Workers subdomains (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), writes it to a temp path under a deceptive name impersonating dotnet diagnostics (dotnet_diag_\u003chex\u003e.exe or.cache_\u003chex\u003e), chmods it 0755, and spawns it detached via cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true}).unref() (or spawn('cmd',...) on Windows). When HTTP fetch fails, a DNS TXT covert channel reassembles a base64 payload from sequential numbered subdomains under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. No hash or signature verification is performed. All C2 hostnames and resolver domains are assembled from split string fragments via.join('') to defeat static analysis. A second parallel dropper in lib/telemetry.js under an 'analytics SDK' cover story implements the same base64-payload / chmod 0755 / cp.spawn('/bin/sh', ['-c', filePath + ' &']) pattern as a backup path. The package name and version have no relationship to legitimate BNPL/desktop tooling; the tarball's only functional effect is remote code execution on the installer's machine.\n","modified":"2026-08-05T15:50:58.351625525Z","published":"2026-08-05T14:49:20Z","database_specific":{"malicious-packages-origins":[{"versions":["35.7.9"],"id":"IN-MAL-2026-015455","import_time":"2026-08-05T15:19:52.398127001Z","modified_time":"2026-08-05T14:49:20Z","sha256":"c8ebc784cdc9c083f42cf6323e773eb7bf43b1b927c936c609bb8d93a90bb4cb","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-desktop-bnpl-container/v/35.7.9"}],"affected":[{"package":{"name":"bnpl-blocks-desktop-bnpl-container","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-desktop-bnpl-container"},"versions":["35.7.9"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"6f6a4cd12cd111167d816ca416ce3e6f1bf8e320455b295284384700827523ec","tlsh":"46a1966a026670188bb0ebe4c7175415f55bf6632380d194fb9c6a985ff2164c3b2efc","path":"_ext.js"},{"tlsh":"33835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js","sha256":"859443ebf05e45bdc1cd325b8465a47841e28193d9f1eee5eb2dc76965fc346a"}],"package_integrity":[{"filename":"bnpl-blocks-desktop-bnpl-container-35.7.9.tgz","hashes":{"sha1":"791e40b9efe186a3af9896034c5d796bf8e8d9c4","sha512_sri":"sha512-HimLt2/6BEQGmvw7mApJdIX4/vHheMJCD12eRTJ0fWeT7QIbaDaXN970KSwMhaj6unmq73Uw+y8UWYkU3RrUjA=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-desktop-bnpl-container/MAL-2026-12919.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}