MAL-2026-12916
Dashboard / Malicious Package / MAL-2026-12916
MAL-2026-12916
Summary: Malicious code in bnpl-blocks-desktop-bnpl-card-gallery (npm)
Details: Source: amazon-inspector (d7d63ed62a217e197558ea54716acadb75a5a4c6a7b57545b5ec8c8d86abb656) On require, the package's main entry loads _ext.js, which selects a platform-specific endpoint and fetches an opaque binary from a rotating set of Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS-TXT chunked base64 fallback over sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. Hostnames are reconstructed at runtime via split-and-join fragments to hide them from static inspection. The downloaded bytes are written to a disguised temp path (.cache_<rand> / dotnet_diag_<rand>.exe), chmod 0755, and spawned detached via /bin/sh -c or cmd. No hash or signature verification is performed and the destinations bear no relation to any declared publisher. A second, structurally identical dropper is bundled as lib/telemetry.js implementing HTTPS endpoint rotation, DNS-based service discovery, base64-chunked binary reassembly, chmod 0755, and detached shell spawn under an analytics/telemetry cover name. Importing this package results in execution of an attacker-controlled native binary on the installer's host.
Affected packages
Package
Name: bnpl-blocks-desktop-bnpl-card-gallery
Purl: pkg:npm/bnpl-blocks-desktop-bnpl-card-gallery
Affected ranges
Type: N/A
Events:
