{"id":"MAL-2026-12986","summary":"Malicious code in bnpl-blocks-mobile-bnpl-documents (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (988d216f062a1183358e442ea59c16497355dea792b1be8a7de103de649f2f56)\nThe package's main entry require()s./_compat on load. _compat.js runs an async init() at module load that fetches an opaque binary from hardcoded Cloudflare Workers subdomains (oob-worker.cf*.workers.dev), with a DNS-TXT fallback under sdk.dl.wel1.ru that base64-reassembles bytes. Destination hostnames are string-joined at runtime from substring arrays to defeat static URL scanning. The fetched bytes are written to a temp path under cover-story filenames (dotnet_diag_\u003chex\u003e.exe on Windows,.cache_\u003chex\u003e on Unix), chmod 0755'd, and launched detached and unref'd via cmd.exe /c start /b or /bin/sh -c '\u003cpath\u003e &'. A second dropper implementation in lib/telemetry.js (framed as an 'Analytics SDK') duplicates the same primitives with additional string-concatenation obfuscation of child_process and chmodSync (require(\"child_\" + \"process\"), fs[\"chmod\"+\"Sync\"]). Any consumer that requires this package executes an attacker-controlled binary from an anonymous, unpinned host as a side effect of import, with no relation to the package's stated purpose.\n","modified":"2026-08-05T15:51:29.183342701Z","published":"2026-08-05T14:39:51Z","database_specific":{"malicious-packages-origins":[{"versions":["35.1.2"],"id":"IN-MAL-2026-015391","import_time":"2026-08-05T15:19:48.868025301Z","modified_time":"2026-08-05T14:39:51Z","sha256":"988d216f062a1183358e442ea59c16497355dea792b1be8a7de103de649f2f56","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-mobile-bnpl-documents/v/35.1.2"}],"affected":[{"package":{"name":"bnpl-blocks-mobile-bnpl-documents","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-mobile-bnpl-documents"},"versions":["35.1.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"bnpl-blocks-mobile-bnpl-documents-35.1.2.tgz","hashes":{"sha512_sri":"sha512-9TKPuLec5WbkILFP3K8OwedMzJvnBmaFX3YhX3kylW0IvOMZr0QqCypXdIA6kncF8CvOU3GNJp7Oxyhp7Sj2bQ==","sha1":"651a9858a79ff66020a579d75521ba958d53dc36"}}],"evidence_files":[{"sha256":"51058f37d27dde5c67d6624d256d45ae027faa5b39230bbb463da6b9f582116a","tlsh":"99a1b79a16a6700887b097e487174415f65ff66337c0c2d4f79ca5985fb25248372efc","path":"_compat.js"},{"sha256":"2624842f9bd53c3594ee351b542f1ff901d3c12a54405a8c9b645225905072e1","tlsh":"ec835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-mobile-bnpl-documents/MAL-2026-12986.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}