MAL-2026-12911
Dashboard / Malicious Package / MAL-2026-12911
MAL-2026-12911
Summary: Malicious code in bnpl-blocks-desktop-bnpl-action-panel (npm)
Details: Source: amazon-inspector (6a42e260d378e0b517e59b4656f10bb75ffe083a5f8431b4d6a908ec4dae0cb0) On require() of the package's main entry, _compat.js reconstructs Cloudflare Workers hostnames (oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev) from split string fragments joined at runtime, downloads a platform-specific binary via https.get, writes it to a temp path disguised as a system file (`.cache_<hex>` on unix, `dotnet_diag_<hex>.exe` on Windows), chmods it 0755, and spawns it detached via `/bin/sh -c` on unix or `cmd /c start /b` on Windows. If the HTTPS fetch fails, the code falls back to a DNS-over-TXT channel querying chunked TXT records under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, base64-decodes the concatenated chunks, and uses the result as the executable payload. The `child_process` module is likewise obtained via `require("child_"+"process")` in a sibling telemetry file, and cover-story comments label the behavior as analytics/telemetry. The runtime string reconstruction of destinations, disguised filenames, detached-spawn pattern, and DNS-TXT egress-bypass channel are consistent with a load-time remote code execution dropper against any host that installs or imports this package.
Affected packages
Package
Name: bnpl-blocks-desktop-bnpl-action-panel
Purl: pkg:npm/bnpl-blocks-desktop-bnpl-action-panel
Affected ranges
Type: N/A
Events:
