{"id":"MAL-2026-13000","summary":"Malicious code in bnpl-blocks-mobile-bnpl-partners (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6e19ad8f13f3c9f4ab6b31c65bad3fb1239ad816c040504428eae8c32740869c)\nindex.js unconditionally requires _helpers.js, which on module load fetches a platform-specific binary from string-split-obfuscated Cloudflare Workers subdomains (oob-worker.cf*.workers.dev) with a DNS/TXT fallback under *.dl.wel1.ru, writes the payload to /var/tmp or %TEMP% under cover-story filenames (.cache_\u003chex\u003e on Linux, dotnet_diag_\u003chex\u003e.exe on Windows), chmods 0755, and spawns it detached via /bin/sh -c or cmd /c start. Hostnames are assembled at runtime from split arrays joined with.join('') to hide the destinations from static scanners, and cp/fs API names are reconstructed via string concatenation (require('child_'+'process'), fs['chmod'+'Sync']). A parallel dropper implementation is bundled in lib/telemetry.js under an 'analytics SDK' cover story with the same fetch, base64-decode, chmod 755, and detached-shell-spawn primitives. Requiring this package on any platform executes attacker-controlled code on the installer's host.\n","modified":"2026-08-05T15:51:36.014197147Z","published":"2026-08-05T14:37:51Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T14:37:51Z","sha256":"6e19ad8f13f3c9f4ab6b31c65bad3fb1239ad816c040504428eae8c32740869c","source":"amazon-inspector","versions":["35.8.8"],"id":"IN-MAL-2026-015377","import_time":"2026-08-05T15:19:48.091491297Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-mobile-bnpl-partners/v/35.8.8"}],"affected":[{"package":{"name":"bnpl-blocks-mobile-bnpl-partners","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-mobile-bnpl-partners"},"versions":["35.8.8"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"_helpers.js","sha256":"6a890813c030229a47c5599c4cb3fabd08e9178973e6b6f4a23c93861ce3738b","tlsh":"2bb1865a12a570284ab0e7e0c61b5816f66af76337c0c1d4fb9c69985f7362483b1dfc"},{"sha256":"4a4da36bdd754dccf364f48203608e3b2bb05e7b6f753362da7217664ed57c9c","tlsh":"88835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}],"package_integrity":[{"filename":"bnpl-blocks-mobile-bnpl-partners-35.8.8.tgz","hashes":{"sha1":"1cb295ef431c1a9cb42571a0fc3f53d10c6599a2","sha512_sri":"sha512-Jbiy3rJax7DtfDi7DiOIDg/+khn1FiXauX6iZBFgnI9/vZwJK7C4Ys/ugjGmzMHX1uipfOq/XlXzi9h4KB2J/w=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-mobile-bnpl-partners/MAL-2026-13000.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}