{"id":"MAL-2026-12938","summary":"Malicious code in bnpl-blocks-desktop-bnpl-reviews (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (eaa5e2ca983c49eefb3d32e333435a236f63c2d896ac41aed7b56114c477964c)\nOn require, index.js loads _init.js which reconstructs a set of hostnames from split-string fragments (e.g. 'oob-worker.cf103-','070','.wo','rker','s.dev' and 'sdk.dl','.wel1.','ru'), downloads a per-architecture binary over HTTPS, writes it to /var/tmp or %TEMP% under a disguised name (dotnet_diag_\u003crnd\u003e.exe or.cache_\u003crnd\u003e), chmods it 0755, and spawns it detached via child_process spawn('/bin/sh', ['-c', \u003cpath\u003e+' &']) or spawn('cmd',...). If the HTTPS fetch fails, the loader queries DNS TXT records at c.\u003cdomain\u003e for a chunk count and then j.\u003cdomain\u003e to reassemble a base64-encoded payload, providing a covert delivery channel that bypasses HTTP egress filters. The child_process module name and destination hostnames are both split and joined at runtime to evade static analysis, and a cover-story 'analytics_state' / 'DISABLE_TELEMETRY' TTL marker is used to disguise intent. This behavior fires automatically on module load with no relation to any advertised package purpose.\n","modified":"2026-08-05T15:51:07.434041255Z","published":"2026-08-05T14:46:39Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.6.5"],"id":"IN-MAL-2026-015437","import_time":"2026-08-05T15:19:51.354893775Z","modified_time":"2026-08-05T14:46:39Z","sha256":"eaa5e2ca983c49eefb3d32e333435a236f63c2d896ac41aed7b56114c477964c"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-desktop-bnpl-reviews/v/35.6.5"}],"affected":[{"package":{"name":"bnpl-blocks-desktop-bnpl-reviews","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-desktop-bnpl-reviews"},"versions":["35.6.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-desktop-bnpl-reviews/MAL-2026-12938.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"_init.js","sha256":"a234ea32d4f35261e8b630405e3380dc2023b1927934bd4b08b1458635759e5b","tlsh":"b6a1955b16a6b0184bb0ebe4c6178826f65bf66337808694f79c65980f735248372efc"}],"package_integrity":[{"filename":"bnpl-blocks-desktop-bnpl-reviews-35.6.5.tgz","hashes":{"sha1":"8fdd777c307cf90dc3aa4f014753351f51b9a7ac","sha512_sri":"sha512-D/4qQmePT+NIEHXN48jAcZD5sqZxpweLxTGHzY2scrxeik3Ka/wTHZhquuwZrv2qrAyP7qGVqffQiUYN0XJbsA=="}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}