{"id":"MAL-2026-12993","summary":"Malicious code in bnpl-blocks-mobile-bnpl-image-plus-text (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1fe5dcff2d2c8210499718411ebd66f6810c42a8439728a3919636548598b494)\nOn require of the package, _compat.js assembles remote endpoint hostnames from split string arrays (e.g. oob-worker.cf10x-*.workers.dev) and includes a DNS TXT-record base64 fallback channel over c.\u003cdomain\u003e and numbered subdomains of dl.wel1.ru. It downloads a platform-specific binary from those attacker-controlled hosts with no hash or signature verification, writes it to a temp path under a masquerading name (dotnet_diag_*.exe on Windows,.cache_* on Unix), chmods it 0755, and spawns it detached via cmd.exe /c start /b or /bin/sh -c. The dropper runs on module load with a TTL stamp to suppress re-execution. Behaviors observed include platform gating, cover-story naming, string-concatenation obfuscation of the C2 hosts, and a covert DNS TXT-record fallback for endpoint resolution.\n","modified":"2026-08-05T15:51:32.885168782Z","published":"2026-08-05T14:39:33Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015389","import_time":"2026-08-05T15:19:48.762485079Z","modified_time":"2026-08-05T14:39:33Z","sha256":"1fe5dcff2d2c8210499718411ebd66f6810c42a8439728a3919636548598b494","source":"amazon-inspector","versions":["35.3.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-mobile-bnpl-image-plus-text/v/35.3.2"}],"affected":[{"package":{"name":"bnpl-blocks-mobile-bnpl-image-plus-text","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-mobile-bnpl-image-plus-text"},"versions":["35.3.2"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"9db1965a15b970188bb0d7e087275415f66af663338086d8fb9ca5981f7712483b2dfc","path":"_compat.js","sha256":"59c1aa3a990876e33d7da95fc33814266e0f954c8eca1f5f4874c1aacaaede01"}],"package_integrity":[{"filename":"bnpl-blocks-mobile-bnpl-image-plus-text-35.3.2.tgz","hashes":{"sha512_sri":"sha512-bdF/dXUa/h9qbIFoogoxqACUfWRZOcz9msfOqdSKYQQqN9uRRxPK/xycqr2LIheN2SaXMSSkrK4Efp7E5G8Ucw==","sha1":"bed29924c9288e3fa36697ae23ce458546d2c897"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-mobile-bnpl-image-plus-text/MAL-2026-12993.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}