MAL-2026-12907
Dashboard / Malicious Package / MAL-2026-12907
MAL-2026-12907
Summary: Malicious code in bnpl-blocks-component-story-name (npm)
Details: Source: amazon-inspector (a797e2310dd4df10e11e104dad3fbb135621e9997a5425f480c3c884da59ca6d) On require of this package, index.js loads _polyfill.js which downloads a platform-specific executable from one of four hardcoded Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev), with a DNS-TXT covert-channel fallback that reassembles base64 payload chunks from numeric subdomains of sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The fetched bytes are written to /var/tmp or %TEMP% under disguised names (dotnet_diag_*.exe,.cache_*), chmod 0755, and spawned detached via /bin/sh -c or cmd.exe /c start /b. Destination hostnames are assembled at runtime by joining split string fragments to evade static string scanners. Requiring the package yields arbitrary remote code execution on the installer's host.
Affected packages
Package
Name: bnpl-blocks-component-story-name
Purl: pkg:npm/bnpl-blocks-component-story-name
Affected ranges
Type: N/A
Events:
