MAL-2026-12173

    Dashboard / Malicious Package / MAL-2026-12173

    MAL-2026-12173

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bnpl-blocks-desktop-bnpl-documents (npm)

    Details: Source: amazon-inspector (a4909f4a2b9f9355cd2cbde2b75f8a5d7d3f4ec6b79ed828fdb9cc18b23107e0) On require of the package, index.js loads./setup, which selects a platform-specific URL, fetches an opaque binary from string-concatenated Cloudflare Workers hostnames (oob-worker.cf100-416.workers.dev, cf103-070.workers.dev, cf102-baf.workers.dev), writes it to /var/tmp/.cache_<hex> on POSIX or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh or cmd. Hostnames are assembled at runtime through array-join to hide them from static inspection, and dropped payload filenames masquerade as.NET diagnostics artifacts. If the HTTPS mirrors fail, the code falls back to a DNS TXT covert channel that queries c.<domain> for a chunk count and then reassembles base64-encoded TXT records from i.<domain> across *.dl.well1.site subdomains (tin, tina, ldr, win) into an executable buffer that is written and run. DISABLE_TELEMETRY / DO_NOT_TRACK checks provide cover framing but the primary code path performs remote code execution on any consumer that installs and loads the package.

    Affected packages

    Package

    Name: bnpl-blocks-desktop-bnpl-documents

    Purl: pkg:npm/bnpl-blocks-desktop-bnpl-documents

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    20.7.2
    MAL-2026-12173 | CVE-DB