{"id":"MAL-2026-12974","summary":"Malicious code in bnpl-blocks-independent-bnpl-title (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5e5739a73a4f30d9828f08510a518df278f00214576e8c2aaea847bc536989bd)\nThe package advertises itself as a UI title component but on require() of index.js loads _support.js, which selects a per-OS payload path, fetches an unsigned binary from obfuscated Cloudflare Workers subdomains (oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS-TXT-chunked base64 fallback from *.dl.wel1.ru (sdk/ext/pkg/net.dl.wel1.ru), writes it to /tmp or %TEMP% under a disguising name (e.g..cache_\u003chex\u003e, dotnet_diag_\u003chex\u003e.exe), chmods 0755, and spawns it detached via /bin/sh -c or cmd /c start. Endpoint hostnames and DNS-fallback domains are assembled by.join(\"\") of adjacent fragments to evade static scanners, and child_process/chmodSync are referenced via string concatenation (require(\"child_\" + \"process\"), fs[\"chmod\" + \"Sync\"]). A parallel copy of the same drop-and-exec pattern ships in lib/telemetry.js framed as an 'Analytics SDK'. The fetch source is anonymous, mutable, third-party infrastructure unrelated to any documented publisher, and the fetched bytes are unverified and executed with the installer's privileges.\n","modified":"2026-08-05T15:51:23.446037413Z","published":"2026-08-05T14:42:42Z","database_specific":{"malicious-packages-origins":[{"sha256":"5e5739a73a4f30d9828f08510a518df278f00214576e8c2aaea847bc536989bd","source":"amazon-inspector","versions":["35.2.4"],"id":"IN-MAL-2026-015410","import_time":"2026-08-05T15:19:49.924498964Z","modified_time":"2026-08-05T14:42:42Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-independent-bnpl-title/v/35.2.4"}],"affected":[{"package":{"name":"bnpl-blocks-independent-bnpl-title","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-independent-bnpl-title"},"versions":["35.2.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"bnpl-blocks-independent-bnpl-title-35.2.4.tgz","hashes":{"sha1":"89550ff5cc4332e49821f28bc92b86cd516b7647","sha512_sri":"sha512-BMYQ/vHmROYtqRAoxV6tKlLc81a+zXSUsaM1g8i2imPUfJJ2lueiGo8j9on+tB3ZE1/s9v5G087T8Vphtbhh/Q=="}}],"evidence_files":[{"path":"_support.js","sha256":"469b07332d8cd0485fc4ae08e06cd97205d764d319380467a2e95ded9c68bc43","tlsh":"eba1965a166670188bb0ebf487175819f65bf66333808284fb5c69d41f7716483b2efc"},{"path":"lib/telemetry.js","sha256":"bfd70d523694ccec304491770a0e3ba42dd6429a9a358c978b08537b06f7f0fc","tlsh":"92835055566a202186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-independent-bnpl-title/MAL-2026-12974.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}