{"id":"MAL-2026-12920","summary":"Malicious code in bnpl-blocks-desktop-bnpl-faq (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c0028d1bea265a3e3fdcbbe1d43188f3aef4b4c332a995352c19ac5a090c42ac)\nOn require() of the package, index.js loads _support.js which reconstructs remote hostnames from string-array fragments joined with.join('') to defeat literal-string scanning. It then fetches platform-specific binaries via https.get from oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, and oob-worker.cf100-416.workers.dev, writes them to /var/tmp or %TEMP% under disguised names (.cache_\u003crand\u003e, dotnet_diag_\u003crand\u003e.exe), chmods 0755, and detach-executes them via spawn('/bin/sh') or spawn('cmd'). A DNS-TXT covert channel to sdk.dl.wel1.ru provides an out-of-band fallback for chunked base64 data. A cover-story 'analytics/telemetry' framing wraps the payload with opt-out env-var checks (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) and a hidden run-once marker at /tmp/.analytics_state to reduce repeated observation. The download hosts are not publisher-controlled infrastructure, the fetched bytes are unpinned and unverified, and execution is unconditional at module load.\n","modified":"2026-08-05T15:50:58.498889731Z","published":"2026-08-05T14:50:17Z","database_specific":{"malicious-packages-origins":[{"versions":["35.6.6"],"id":"IN-MAL-2026-015461","import_time":"2026-08-05T15:19:52.709352172Z","modified_time":"2026-08-05T14:50:17Z","sha256":"c0028d1bea265a3e3fdcbbe1d43188f3aef4b4c332a995352c19ac5a090c42ac","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-desktop-bnpl-faq/v/35.6.6"}],"affected":[{"package":{"name":"bnpl-blocks-desktop-bnpl-faq","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-desktop-bnpl-faq"},"versions":["35.6.6"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"bf9e76daa29023dadff220bb0f7288f5808a300ea097513672b0a0ad70634c53","tlsh":"2ca1a59a066570184bb0abe4c61b4816f65bf6633780c2d8f79c65981fb352483b2efc","path":"_support.js"}],"package_integrity":[{"filename":"bnpl-blocks-desktop-bnpl-faq-35.6.6.tgz","hashes":{"sha1":"80b7308caffceeda1a5bad9b9285a618089d3a4d","sha512_sri":"sha512-9cvcTsZ1CnXLCyLfWHlMW2dHByFL+lUKgyAGGIbrnO/z8lwBQgMvnwb5HN1CmAYcWvBlw2nFanDquLPdpYuylA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-desktop-bnpl-faq/MAL-2026-12920.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}