{"id":"MAL-2026-12957","summary":"Malicious code in bnpl-blocks-independent-bnpl-info-slider (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (eabf8fd96af80f1588f7073731f3f670133e10f4c0e553c499081d3cb76b69ca)\nThe package advertises itself as a UI slider component but ships _shim.js, which is loaded via index.js on require. On load, _shim.js fetches a platform-specific binary from hardcoded Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT chunked fallback channel via sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The C2 hostnames and resolver domains are reconstructed at runtime via array-join to evade static analysis. The downloaded binary is written to /var/tmp or the Windows TEMP directory under disguised names such as dotnet_diag_\u003chex\u003e.exe and.cache_\u003chex\u003e, chmod'd to 0755, and spawned detached with stdio ignored. Cover-story naming (analytics, telemetry, DISABLE_TELEMETRY opt-outs) and the DNS-TXT covert delivery channel are anti-analysis techniques. The behavior is unrelated to any legitimate purpose of a UI slider package and provides remote code execution on any host that installs or loads the package.\n","modified":"2026-08-05T15:51:16.049423202Z","published":"2026-08-05T14:45:01Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T14:45:01Z","sha256":"eabf8fd96af80f1588f7073731f3f670133e10f4c0e553c499081d3cb76b69ca","source":"amazon-inspector","versions":["35.9.8"],"id":"IN-MAL-2026-015426","import_time":"2026-08-05T15:19:50.70716756Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-independent-bnpl-info-slider/v/35.9.8"}],"affected":[{"package":{"name":"bnpl-blocks-independent-bnpl-info-slider","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-independent-bnpl-info-slider"},"versions":["35.9.8"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"bnpl-blocks-independent-bnpl-info-slider-35.9.8.tgz","hashes":{"sha512_sri":"sha512-jMasj71+SYEPBJrZsGn6F23Pkh+WwX8rOewYragg9QRCavs/1idwF9f5AmUo9z7Y3R3d9vdgzA7LlEV199wt4w==","sha1":"40d718ddb1f18c698a894c344605f6173f330143"}}],"evidence_files":[{"path":"_shim.js","sha256":"92f70a1f0ed265b03ace36d38c36f718a0e3ccf51becb363686565c0566d24e3","tlsh":"f0a1c79617a630198bb09be0c7174416f65fe6633380c294fb9ca5941fb312483b1efc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-independent-bnpl-info-slider/MAL-2026-12957.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}