{"id":"MAL-2026-12925","summary":"Malicious code in bnpl-blocks-desktop-bnpl-header (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0c6b73a025a319c8c2af1d616239d0950f911030ae9760506d6090be908ca935)\nOn require() of this package, index.js loads _bridge.js, which reconstructs C2 hostnames from split string fragments (e.g. [\"oob-worker\",\".cf\",\"10\",\"3-070.worke\",\"rs.d\",\"ev\"].join(\"\")) to resolve oob-worker.cf*.workers.dev endpoints and a DNS-TXT fallback under *.dl.wel1.ru. It downloads a platform-specific binary (/pkg/package, /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe), writes it to /var/tmp or %TEMP% under a disguised name (.cache_\u003chex\u003e or dotnet_diag_\u003chex\u003e.exe), chmods it 0755, and spawns it detached via /bin/sh or cmd.exe /c start /b, using a marker file to suppress repeat execution. A DNS-TXT channel reassembles base64 chunks from sequentially numbered TXT records as a fallback. Cover strings referencing analytics/telemetry/dotnet_diag are misdirection; the destinations are non-publisher, anonymous Cloudflare Workers and Russian DNS hosts, and the fetched bytes are opaque binaries executed on the installer's host. An additional 81 KB lib/telemetry.js is shipped but not reached from index.js or _bridge.js.\n","modified":"2026-08-05T15:51:02.007507508Z","published":"2026-08-05T14:49:57Z","database_specific":{"malicious-packages-origins":[{"versions":["35.7.1"],"id":"IN-MAL-2026-015459","import_time":"2026-08-05T15:19:52.615120399Z","modified_time":"2026-08-05T14:49:57Z","sha256":"0c6b73a025a319c8c2af1d616239d0950f911030ae9760506d6090be908ca935","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-desktop-bnpl-header/v/35.7.1"}],"affected":[{"package":{"name":"bnpl-blocks-desktop-bnpl-header","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-desktop-bnpl-header"},"versions":["35.7.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"bnpl-blocks-desktop-bnpl-header-35.7.1.tgz","hashes":{"sha512_sri":"sha512-oROiyUsLoLTe3RQ8xehAYz5dtzIhm0V/8TFoLfyjdgk18h1lEJrZL+M1TYDkicebqiEhKyLl58ACXPqHrjcjUA==","sha1":"fb5d86932222cd2c2b264e8773f9e775ebce2381"}}],"evidence_files":[{"tlsh":"89b1a65a16a670188bb097f4c7274416f55be66337c1c2d8fb5ca5d80fb612482b2efc","path":"_bridge.js","sha256":"0b7dac2ddbfa5f512cde2fcff09d77f565966c0465bd61a3e9db55352d98db4e"},{"sha256":"7b226fdf6aee9636b1ef78a51f61acfba19376f42b8191bf748dbdb31d4b7585","tlsh":"7e835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-desktop-bnpl-header/MAL-2026-12925.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}