MAL-2026-12890
Dashboard / Malicious Package / MAL-2026-12890
MAL-2026-12890
Summary: Malicious code in bnpl-blocks-atom-bnpl-review (npm)
Details: Source: amazon-inspector (2251415239635fc707b724b732dcac0bb05e9b6714ad73bc5d6027d6b7247a05) On require() of the package, index.js loads _platform.js which fetches a platform-specific binary from Cloudflare Workers subdomains whose hostnames are assembled at runtime from split string fragments (e.g. oob-worker.cf99-9b3.workers.dev, cf103-070/cf101-adf/cf100-416.workers.dev). If HTTPS fetches fail, the module falls back to a DNS TXT-record covert channel under *.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), reading a chunk count from c.<domain> and base64-decoding concatenated TXT records from numbered subdomains. The retrieved bytes are written to /tmp or %TEMP% under disguised names (.cache_<hex> on Unix, dotnet_diag_<hex>.exe on Windows), chmod 0755, and spawned detached via /bin/sh -c or cmd.exe. No signature or hash verification is performed and the payload is unrelated to the package's advertised BNPL-review purpose. A second copy of the dropper is bundled in lib/telemetry.js (81 KB) wrapped as an APM SDK, containing matching base64 payload assembly, chmod 0755, and /bin/sh -c spawn primitives; it is not reachable from the main entry in this version but mirrors the same infrastructure.
Affected packages
Package
Name: bnpl-blocks-atom-bnpl-review
Purl: pkg:npm/bnpl-blocks-atom-bnpl-review
Affected ranges
Type: N/A
Events:
