{"id":"MAL-2026-13015","summary":"Malicious code in bnpl-blocks-scroll (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (99a0a2e3786f50dc07b4546de5ae22f3a65ad50e95897b8ca4d0fa6460b32d63)\nOn require() of bnpl-blocks-scroll, index.js loads _helpers.js, which selects a platform-specific payload path and fetches an opaque native executable via https.get from one of three Cloudflare Workers hosts whose names are assembled at runtime by joining string fragments (oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev). If the HTTPS mirrors fail, the code reconstructs the payload from base64-encoded DNS TXT records under a platform-specific subdomain of wel1.ru (dns.resolveTxt on c.\u003cdomain\u003e, resolvers themselves assembled by [].join('')). The retrieved bytes are written to /tmp or %TEMP% under disguised names (.cache_\u003chex\u003e on unix, dotnet_diag_\u003chex\u003e.exe on Windows), chmod 0755, then spawned detached via cp.spawn('/bin/sh', ['-c', fp+' &'], {detached:true}).unref() or spawn('cmd',...). A.analytics_state cooldown file and honoring of DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK env vars provide a telemetry cover story that does not match the actual behavior (fetching and executing an unpinned, unverified native binary). Host-name string-splitting, DNS-over-TXT fallback transport, cover-story filenames, and detached execution together constitute a deliberate remote-code-execution dropper against any machine that installs or imports this package.\n","modified":"2026-08-05T15:51:43.407474445Z","published":"2026-08-05T14:36:40Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015369","import_time":"2026-08-05T15:19:47.440391591Z","modified_time":"2026-08-05T14:36:40Z","sha256":"99a0a2e3786f50dc07b4546de5ae22f3a65ad50e95897b8ca4d0fa6460b32d63","source":"amazon-inspector","versions":["35.2.6"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-scroll/v/35.2.6"}],"affected":[{"package":{"name":"bnpl-blocks-scroll","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-scroll"},"versions":["35.2.6"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"_helpers.js","sha256":"8be2460942843f5dc3e558107ff1334d0cb4b4b08be27b6e82f33e31445aef84","tlsh":"99a184aa166a70084fb0ebe1c7174416fa67f66337808695f79c59941fb2124c3b2efc"}],"package_integrity":[{"filename":"bnpl-blocks-scroll-35.2.6.tgz","hashes":{"sha1":"d970e23af3f2f2baf9c001db241d2f48c80a7a52","sha512_sri":"sha512-tcXGb8SorW0Gb8k3ty24E1ljMab3mGAIb5LekkRUOfzR3JG2oFIjwQJNi+aNqLQVJryZGOjexXBBrZ/aklP3fw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-scroll/MAL-2026-13015.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}