{"id":"MAL-2026-12967","summary":"Malicious code in bnpl-blocks-independent-bnpl-product-grid (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (398d16a0c0dbc5af823fe61d71d41dffc0bbaac820b948fb9310a250e2ed966e)\nThe package advertises a BNPL product-grid block, but top-level require('./_platform') from index.js triggers _platform.js, which on load selects a platform-specific endpoint, downloads an opaque binary over HTTPS from Cloudflare Workers hosts, writes it to /var/tmp or %TEMP% under disguise filenames (.cache_*, dotnet_diag_*.exe), chmods it 0o755, and spawns it detached via /bin/sh or cmd. Destination hostnames are reconstructed at runtime by concatenating string fragments (e.g. ['oob-w','orker.cf100-416.work','ers.de','v'].join(''); ['sdk.dl.wel1.','ru'].join('')) to evade static analysis. If the HTTPS fetch fails, the module falls back to a DNS TXT channel: it resolves c.\u003cdomain\u003e for a chunk count, batches TXT lookups against N.\u003cdomain\u003e under *.dl.wel1.ru, base64-decodes the concatenated response into a Buffer, and executes those bytes through the same activation path. No hash or signature verification is performed, the delivery infrastructure is unrelated to the advertised BNPL purpose, and DO_NOT_TRACK / DISABLE_TELEMETRY env gates serve as cover.\n","modified":"2026-08-05T15:51:20.792620454Z","published":"2026-08-05T14:44:09Z","database_specific":{"malicious-packages-origins":[{"versions":["35.5.5"],"id":"IN-MAL-2026-015420","import_time":"2026-08-05T15:19:50.391232358Z","modified_time":"2026-08-05T14:44:09Z","sha256":"398d16a0c0dbc5af823fe61d71d41dffc0bbaac820b948fb9310a250e2ed966e","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-independent-bnpl-product-grid/v/35.5.5"}],"affected":[{"package":{"name":"bnpl-blocks-independent-bnpl-product-grid","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-independent-bnpl-product-grid"},"versions":["35.5.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-independent-bnpl-product-grid/MAL-2026-12967.json","indicators":{"package_integrity":[{"hashes":{"sha1":"90f22c9872952165cb37890b7ca8c527383dc346","sha512_sri":"sha512-XqS6M97UoeSYSPNhWxf49QtcN+q3b2mYrR9wTOaorsdvnPxsE4+tLa2Hl5IycSyFs0jmBvEPv1RLJbn2IuxXrQ=="},"filename":"bnpl-blocks-independent-bnpl-product-grid-35.5.5.tgz"}],"evidence_files":[{"tlsh":"bca1a79a11aa71188bb0a7e4c7179419f65af7633381c289fb6c95841fb3024c3b1efc","path":"_platform.js","sha256":"77e4d4b866588a03097209b5b20b938a1c9c91afffe3bbaa5764fe59045938ba"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}