{"id":"MAL-2026-12947","summary":"Malicious code in bnpl-blocks-feature-partners (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (40f5d479d4fbf50975912fcbb27c8a3638cfeef78c8bd8a2e666162756abc788)\nindex.js unconditionally require()'s./_ext.js, which on load selects a platform-specific endpoint, fetches an opaque binary from Cloudflare Workers hosts (oob-worker.cf10{1,2,3}-*.workers.dev) reassembled from split string literals, with a DNS-TXT chunked base64 fallback via *.dl.wel1.ru subdomains, writes the payload to /var/tmp/.cache_\u003chex\u003e on Unix or %TEMP%\\dotnet_diag_\u003chex\u003e.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. Network destinations and sensitive API names (child_process, chmodSync) are reconstructed at runtime from split-string arrays to evade static scanners. No integrity check, no hash/signature verification, filename disguises (.cache_ / dotnet_diag_) mimic system caches, and the fetched code is unrelated to any stated package purpose. The dropper fires on any require() of this package.\n","modified":"2026-08-05T15:51:11.494112413Z","published":"2026-08-05T14:46:18Z","database_specific":{"malicious-packages-origins":[{"versions":["35.9.1"],"id":"IN-MAL-2026-015435","import_time":"2026-08-05T15:19:51.243519628Z","modified_time":"2026-08-05T14:46:18Z","sha256":"40f5d479d4fbf50975912fcbb27c8a3638cfeef78c8bd8a2e666162756abc788","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-feature-partners/v/35.9.1"}],"affected":[{"package":{"name":"bnpl-blocks-feature-partners","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-feature-partners"},"versions":["35.9.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-m7qvZAqYxQwCBuaaY61NDhMKqsDqVRp7eFWM5S1QnqqZFc2DJlEPf59STJuFZexVJ7E0xeGtkUo/v0aqJNc+VA==","sha1":"ebdbee1f5a8395e0decce72daf62929759edf129"},"filename":"bnpl-blocks-feature-partners-35.9.1.tgz"}],"evidence_files":[{"sha256":"5614efb0467b089f2ac66ef2ffc06c5e241a1fa1b073e3234864d745bfaed131","tlsh":"f2a1a8aa066630084bb0d7e5c617541af65bf6633780d2d4fb5c65981fb252483f2efc","path":"_ext.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-feature-partners/MAL-2026-12947.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}