MAL-2026-12907

    Dashboard / Malicious Package / MAL-2026-12907

    MAL-2026-12907

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bnpl-blocks-component-story-name (npm)

    Details: Source: amazon-inspector (a797e2310dd4df10e11e104dad3fbb135621e9997a5425f480c3c884da59ca6d) On require of this package, index.js loads _polyfill.js which downloads a platform-specific executable from one of four hardcoded Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev), with a DNS-TXT covert-channel fallback that reassembles base64 payload chunks from numeric subdomains of sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The fetched bytes are written to /var/tmp or %TEMP% under disguised names (dotnet_diag_*.exe,.cache_*), chmod 0755, and spawned detached via /bin/sh -c or cmd.exe /c start /b. Destination hostnames are assembled at runtime by joining split string fragments to evade static string scanners. Requiring the package yields arbitrary remote code execution on the installer's host.

    Affected packages

    Package

    Name: bnpl-blocks-component-story-name

    Purl: pkg:npm/bnpl-blocks-component-story-name

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.2.7