MAL-2026-12906

    Dashboard / Malicious Package / MAL-2026-12906

    MAL-2026-12906

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bnpl-blocks-block (npm)

    Details: Source: amazon-inspector (6112720c2d716ce25da42abf8ddd7ec3e27614102f343c283160f28d8b039ef7) On require of the package, index.js loads./_compat.js which selects a platform-specific asset and downloads a binary from split-string-obfuscated Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev), with a DNS-TXT covert-channel fallback under *.wel1.ru that reads a chunk count from c.<domain> and base64-reassembles the payload from numbered TXT records. The fetched bytes are written to /tmp or %TEMP% under a disguised name (.cache_<hex> / dotnet_diag_<hex>.exe), chmod 0755, then executed detached via /bin/sh -c "<path> &" on POSIX or cmd.exe /c start on Windows. The package's public API (class BnplBlocksBlock with init/version/configure) is a hollow shell with no real implementation; the sole effect of installing or importing this package is running the remotely fetched binary on the installer's host.

    Affected packages

    Package

    Name: bnpl-blocks-block

    Purl: pkg:npm/bnpl-blocks-block

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.8.9
    MAL-2026-12906 | CVE-DB