{"id":"MAL-2026-12988","summary":"Malicious code in bnpl-blocks-mobile-bnpl-feedback (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (28f1214c6f46b90fa1bf81bde9a79c81a5193e84969ef756f50cbf895c49515b)\nOn require of the package, index.js loads _shim.js which selects a platform-specific binary from a list of string-split-obfuscated Cloudflare Workers hosts (reassembled at runtime, e.g. oob-worker.cf99-9b3.workers.dev), with a DNS-TXT chunked-base64 fallback across wel1.ru subdomains (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru; count served at c.\u003cdomain\u003e, parts at N.\u003cdomain\u003e). The retrieved payload is written to /tmp or %TEMP% under cover names resembling system tooling (dotnet_diag_*.exe,.cache_*), chmodded 0755 on POSIX, and spawned detached via spawn(\"/bin/sh\",[\"-c\", path+\" &\"],{detached:true}) or spawn(\"cmd\",...) on Windows. The destinations are obfuscated, unrelated to any legitimate publisher, and the executed bytes are attacker-controlled.\n","modified":"2026-08-05T15:51:30.332563863Z","published":"2026-08-05T14:41:24Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.3.5"],"id":"IN-MAL-2026-015401","import_time":"2026-08-05T15:19:49.369684619Z","modified_time":"2026-08-05T14:41:24Z","sha256":"28f1214c6f46b90fa1bf81bde9a79c81a5193e84969ef756f50cbf895c49515b"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-mobile-bnpl-feedback/v/35.3.5"}],"affected":[{"package":{"name":"bnpl-blocks-mobile-bnpl-feedback","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-mobile-bnpl-feedback"},"versions":["35.3.5"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"_shim.js","sha256":"5e8a3d5214ba7c3e458bbe888966db9676614fb5313709925b508c935a7fca4f","tlsh":"77b1985a166670184bb0d7e4cb1b8825f56ef6533781c284f79c65885f7352483b2efc"}],"package_integrity":[{"filename":"bnpl-blocks-mobile-bnpl-feedback-35.3.5.tgz","hashes":{"sha1":"3438ece4d334b9baee0be5ee9922c4414d4cab92","sha512_sri":"sha512-mZrvdoQGjhbgX8EShGmlC3tyI9bKboa5gXyoPSpM44v1cc2boGKZXRS0w0R+UXypXKC0pCwSoO94ZwgYu+sAAg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-mobile-bnpl-feedback/MAL-2026-12988.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}