{"id":"MAL-2026-13026","summary":"Malicious code in bnpl-molecule-mobile-bnpl-selector (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (daf9828096a3c18e00ad577689ebcf4e4fa304a8702db4a0993063c95182530e)\nOn require() of the package, index.js loads _adapter.js, which runs an asynchronous dropper: it selects a platform-specific asset, downloads an executable via https.get from one of three Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev), writes the payload to /var/tmp/.cache_\u003chex\u003e with chmod 0755 on Unix or to the Windows temp directory as dotnet_diag_\u003chex\u003e.exe (masquerading as a.NET diagnostic tool), and spawns it detached via /bin/sh -c '\u003cpath\u003e &' or cmd.exe /c start /b. Destination hostnames, the child_process require, and chmodSync are hidden behind array-join string splits (e.g. \"child_\"+\"process\", [\"oob-worker.cf102-baf.wor\",\"kers\",\".d\",\"ev\"].join(\"\")). A DNS-over-TXT fallback resolves c.sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru for a chunk count, then reassembles a base64 payload from numbered TXT records under those subdomains and executes it identically, providing a covert transport that evades HTTP egress filtering. The dropper is framed with a fake \"Analytics SDK\" / DISABLE_TELEMETRY cover story. A second copy of the same dropper primitives is bundled under lib/telemetry.js (~81 KB) but is not required on the current execution path.\n","modified":"2026-08-05T15:51:48.414463456Z","published":"2026-08-05T14:33:07Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.1.1"],"id":"IN-MAL-2026-015346","import_time":"2026-08-05T15:19:46.089617779Z","modified_time":"2026-08-05T14:33:07Z","sha256":"daf9828096a3c18e00ad577689ebcf4e4fa304a8702db4a0993063c95182530e"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-molecule-mobile-bnpl-selector/v/35.1.1"}],"affected":[{"package":{"name":"bnpl-molecule-mobile-bnpl-selector","ecosystem":"npm","purl":"pkg:npm/bnpl-molecule-mobile-bnpl-selector"},"versions":["35.1.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-molecule-mobile-bnpl-selector/MAL-2026-13026.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"66a73f049edb4e6f56931250fa42fae543cd2959","sha512_sri":"sha512-SLqjMqM8gxO7nrgHeZ5n92lAIafpZNEyQyVfF8lfNre1qexGXLhNFd61yCuYope93zI5fNr4Yz7BwqmpxlVD0g=="},"filename":"bnpl-molecule-mobile-bnpl-selector-35.1.1.tgz"}],"evidence_files":[{"sha256":"f19e57f1f65bb8613b3dc56d1bed5c743e800d684a5d6d36900416a89101c146","tlsh":"fda1749a16a670188bb0abf587164416f65af66337c0d2d4f79c69884fb312483b1efc","path":"_adapter.js"},{"path":"lib/telemetry.js","sha256":"bc39b107e5041e56eeecd1e857e0e1756b32992523c59d698ebbfd9969f80245","tlsh":"0d835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}