{"id":"MAL-2026-13002","summary":"Malicious code in bnpl-blocks-mobile-bnpl-popup (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a02f6576518bfc325248a8787aff66ebad12acc3e63b05fd7b35f96ffd1a62d6)\nThe package's index.js require()s _runtime.js on load, which fetches a platform-specific native binary from one of three Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS TXT chunked-transfer fallback via *.dl.wel1.ru subdomains, writes the bytes to /tmp or %TEMP% under a cover-story name (dotnet_diag_\u003chex\u003e.exe,.cache_\u003chex\u003e), chmods 0755, and spawns the file detached via cp.spawn(\"/bin/sh\", [\"-c\", fp + \" &\"]).unref() and cmd equivalents on Windows. No hash or signature verification is performed; destination hostnames are reconstructed at runtime via array split-and-join to defeat string scanners; opt-out env vars (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) and a /tmp/.analytics_state freshness marker frame the drop as telemetry. A parallel dropper implementation is bundled at lib/telemetry.js (81KB) with the same drop-and-exec shape and additional string-concatenation obfuscation of child_process and chmodSync. The destinations are attacker-controlled and unrelated to any advertised BNPL/popup SDK function; any require() of this package results in native code execution on the installer's machine.\n","modified":"2026-08-05T15:51:37.021772572Z","published":"2026-08-05T14:37:41Z","database_specific":{"malicious-packages-origins":[{"versions":["35.5.9"],"id":"IN-MAL-2026-015376","import_time":"2026-08-05T15:19:48.05168556Z","modified_time":"2026-08-05T14:37:41Z","sha256":"a02f6576518bfc325248a8787aff66ebad12acc3e63b05fd7b35f96ffd1a62d6","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-mobile-bnpl-popup/v/35.5.9"}],"affected":[{"package":{"name":"bnpl-blocks-mobile-bnpl-popup","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-mobile-bnpl-popup"},"versions":["35.5.9"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"f5a5e4dce0ae58cb51b22b87848343d55f34f1887ced1e2e365d55b3fff68383","tlsh":"12a1979a16a670084bb0abe48b178425f55ff6633780c2d4fb5ca5985f7312483b2efc","path":"_runtime.js"},{"path":"lib/telemetry.js","sha256":"13e15562f63f136ed2e1e23281d17e96e209120246d56c59f9fe4b8deec17234","tlsh":"73835056566a502186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"bnpl-blocks-mobile-bnpl-popup-35.5.9.tgz","hashes":{"sha1":"13b22fef4913eb07a2c35a642207e4d7d53aba1e","sha512_sri":"sha512-FVWUpijvTUKz3LZnMQWS7mNs76shXfpplyfTrBRk+sEf4dBV7grUjFc2WVFqiSKlD3ic+y7BZ85h1BbDoYIAzg=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-mobile-bnpl-popup/MAL-2026-13002.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}