{"id":"MAL-2026-12951","summary":"Malicious code in bnpl-blocks-independent-bnpl-button (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7749e7f4c01551d7ec3463d1b65e3f564a9ec64cbc4801586a72652ab55e4e34)\nOn require of the package main, _runtime.js selects a per-OS endpoint, fetches an opaque executable from obfuscated Cloudflare Workers hosts (hostnames assembled by string-splitting, e.g. 'oob-worker.cf100-416.workers.dev') with a DNS-TXT base64-chunked fallback via *.dl.wel1.ru, writes the payload to /var/tmp or the Windows temp directory under disguised names such as 'dotnet_diag_\u003chex\u003e.exe' and '.cache_\u003chex\u003e', chmods it to 0755, and detach-spawns it via cp.spawn('/bin/sh', ['-c', \u003cpath\u003e+' &'], {detached:true}).unref() or spawn('cmd',...). A second dropper module, lib/telemetry.js, is shipped alongside and implements the same base64-chunked payload -\u003e writeFile -\u003e chmodSync -\u003e '/bin/sh -c \u003cpath\u003e &' pattern, with obfuscated identifiers such as require('child_'+'process') and fs['chmod'+'Sync']. Hostname reconstruction via array joins, a no-op logger that suppresses output, disguised filenames, DNS-TXT covert-channel fallback, and detached execution are consistent with an install/load-time remote code execution dropper.\n","modified":"2026-08-05T15:51:13.285200530Z","published":"2026-08-05T14:45:17Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T15:19:50.887017403Z","modified_time":"2026-08-05T14:45:17Z","sha256":"7749e7f4c01551d7ec3463d1b65e3f564a9ec64cbc4801586a72652ab55e4e34","source":"amazon-inspector","versions":["35.2.2"],"id":"IN-MAL-2026-015428"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-independent-bnpl-button/v/35.2.2"}],"affected":[{"package":{"name":"bnpl-blocks-independent-bnpl-button","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-independent-bnpl-button"},"versions":["35.2.2"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"764ad4d58ed1f745412071afabdbef34fa688544b38f31e00c2f67b3269295cd","tlsh":"0ab1b76a06a670084b70d7e4c6175416f666f6633780c198f7ac69881ff712483f2efc","path":"_runtime.js"},{"path":"lib/telemetry.js","sha256":"e3eb06400ac6b52c39db91b261bee252e2c28102bdfaba70b070b725dc8e26fa","tlsh":"de835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-fRZM2PH2ZeyIuO6/k9mY8V2Nw8i2/s8kG82WKnOEUcZ6RTgeiPkbbmdKvW+6xk1iUghh9b8MzmSqrhZ9aNZiow==","sha1":"1b41bdd8cc3d1007a430c87a859ef64fa7e5c9cd"},"filename":"bnpl-blocks-independent-bnpl-button-35.2.2.tgz"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-independent-bnpl-button/MAL-2026-12951.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}