{"id":"MAL-2026-12955","summary":"Malicious code in bnpl-blocks-independent-bnpl-faq (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (62fa2b8c94722055f1345a068fc74b842d0fe8120702208c73f2defd93744194)\nOn require() of this package, index.js loads _runtime.js which downloads a platform-specific binary over HTTPS from obfuscated hosts (oob-worker.cf\u003cn\u003e-\u003cn\u003e.workers.dev, assembled by joining fragmented string arrays to evade static scans), writes it to a disguised path in /tmp or %TEMP% (e.g..cache_\u003chex\u003e or dotnet_diag_\u003chex\u003e.exe), chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. If HTTPS fails, _runtime.js falls back to reassembling a base64-encoded binary from DNS TXT records under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru subdomains and executes it via the same path. No hash or signature verification is performed, and destination hostnames are hidden via array-join obfuscation. The package advertises itself as a BNPL FAQ adapter; the declared purpose does not require binary downloads or a DNS covert channel.\n","modified":"2026-08-05T15:51:15.690051512Z","published":"2026-08-05T14:45:26Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T15:19:50.925552417Z","modified_time":"2026-08-05T14:45:26Z","sha256":"62fa2b8c94722055f1345a068fc74b842d0fe8120702208c73f2defd93744194","source":"amazon-inspector","versions":["35.1.1"],"id":"IN-MAL-2026-015429"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-independent-bnpl-faq/v/35.1.1"}],"affected":[{"package":{"name":"bnpl-blocks-independent-bnpl-faq","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-independent-bnpl-faq"},"versions":["35.1.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-independent-bnpl-faq/MAL-2026-12955.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"bnpl-blocks-independent-bnpl-faq-35.1.1.tgz","hashes":{"sha1":"3235234ea5394a985925f637758bd69ce2dde126","sha512_sri":"sha512-U4qopSYozwWwq0wfzNvpA55gl2r3RqtYMtjCkKSLMBw59JEW5RRrYp/pFcoD7uI5YrrdMJ6YlzL4qwGhIAQaqg=="}}],"evidence_files":[{"tlsh":"1ca1b696126a300847b097e4c71b9416f65bf7633780c685fb6ca5981fb712883b2efc","path":"_runtime.js","sha256":"2280aae45ad8945d9c6bc290c05b3bad545a00308241e384c0dfadc55be4c674"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}