{"id":"MAL-2026-12959","summary":"Malicious code in bnpl-blocks-independent-bnpl-main-banner (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (37df8b5a29c08cca1da2d6cc77c5672f9c23ce6877b148c3bef277d0dbaa1d4e)\nindex.js requires./_polyfill on module load. _polyfill.js selects a platform-specific branch (linux_x64, linux_arm64, darwin, win32), assembles destination hostnames via per-character string joins (e.g. Cloudflare Workers hosts under oob-worker.cf*.workers.dev and a discovery domain under sdk.dl.wel1.ru), downloads an opaque binary, writes it to /tmp or %TEMP% under a disguised name such as.cache_\u003crand\u003e or dotnet_diag_\u003crand\u003e.exe, chmods 0755 on Unix, and spawns it detached via /bin/sh -c '\u003cpath\u003e &' or cmd /c start. A DNS TXT fallback reconstructs the payload from base64-chunked TXT records served across numbered subdomains (c.\u003cdomain\u003e for count, i.\u003cdomain\u003e pieces joined and base64-decoded) when HTTPS retrieval is blocked. The destinations are non-publisher, string-obfuscated hosts; the fetched bytes are executed on the installer's machine at library load with no signature, hash, or publisher verification.\n","modified":"2026-08-05T15:51:17.103015555Z","published":"2026-08-05T14:44:41Z","database_specific":{"malicious-packages-origins":[{"sha256":"37df8b5a29c08cca1da2d6cc77c5672f9c23ce6877b148c3bef277d0dbaa1d4e","source":"amazon-inspector","versions":["35.4.4"],"id":"IN-MAL-2026-015424","import_time":"2026-08-05T15:19:50.631237182Z","modified_time":"2026-08-05T14:44:41Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-independent-bnpl-main-banner/v/35.4.4"}],"affected":[{"package":{"name":"bnpl-blocks-independent-bnpl-main-banner","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-independent-bnpl-main-banner"},"versions":["35.4.4"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"952c6df27be71d3365a610759aee5ce0cf6b2b91b402434f98b4365040656eea","tlsh":"8ba1969a16aa31188bb0a7e4c7175416f55bf2633380c2d4f79c65985fb31248372efc","path":"_polyfill.js"}],"package_integrity":[{"hashes":{"sha1":"c62921a17e53200ad8cf0ed4ee65662550097579","sha512_sri":"sha512-ZobvFUFeOVhOoa57Zsi+mAwSWE+hsQalYAbP/JyWXvDP4A9dJgDTUxWzc2hCzJANr6MWgG5Ifj0qBv/PNw7row=="},"filename":"bnpl-blocks-independent-bnpl-main-banner-35.4.4.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-independent-bnpl-main-banner/MAL-2026-12959.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}