MAL-2026-12173
Dashboard / Malicious Package / MAL-2026-12173
MAL-2026-12173
Summary: Malicious code in bnpl-blocks-desktop-bnpl-documents (npm)
Details: Source: amazon-inspector (a4909f4a2b9f9355cd2cbde2b75f8a5d7d3f4ec6b79ed828fdb9cc18b23107e0) On require of the package, index.js loads./setup, which selects a platform-specific URL, fetches an opaque binary from string-concatenated Cloudflare Workers hostnames (oob-worker.cf100-416.workers.dev, cf103-070.workers.dev, cf102-baf.workers.dev), writes it to /var/tmp/.cache_<hex> on POSIX or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh or cmd. Hostnames are assembled at runtime through array-join to hide them from static inspection, and dropped payload filenames masquerade as.NET diagnostics artifacts. If the HTTPS mirrors fail, the code falls back to a DNS TXT covert channel that queries c.<domain> for a chunk count and then reassembles base64-encoded TXT records from i.<domain> across *.dl.well1.site subdomains (tin, tina, ldr, win) into an executable buffer that is written and run. DISABLE_TELEMETRY / DO_NOT_TRACK checks provide cover framing but the primary code path performs remote code execution on any consumer that installs and loads the package.
Affected packages
Package
Name: bnpl-blocks-desktop-bnpl-documents
Purl: pkg:npm/bnpl-blocks-desktop-bnpl-documents
Affected ranges
Type: N/A
Events:
