MAL-2026-12921
Dashboard / Malicious Package / MAL-2026-12921
MAL-2026-12921
Summary: Malicious code in bnpl-blocks-desktop-bnpl-feedback (npm)
Details: Source: amazon-inspector (7a55a8b87f5fcabb03e7b44b8f85aafe3a6b8a6a1f8799305b21544055e99845) index.js require()s./_init on load. _init.js downloads a platform-specific binary from string-split-obfuscated Cloudflare Workers hosts (oob-worker.cf101-*.workers.dev, oob-worker.cf102-*.workers.dev, oob-worker.cf103-*.workers.dev) via https.get, writes it to /var/tmp or %TEMP% under a disguised name (dotnet_diag_<rand>.exe on Windows,.cache_<rand> on Linux/macOS), chmods it 0755, and spawns it detached via cp.spawn('/bin/sh',['-c', fp+' &']) or spawn('cmd',...). A DNS-TXT covert-channel fallback resolves chunked base64 payloads from *.dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru) via dns.resolveTxt, reassembles them, writes and executes the reconstructed buffer. Destination hostnames are assembled at runtime via Array.join from split fragments to evade static analysis, no version pin, no hash or signature verification, and a TTL marker suppresses re-execution. Full remote code execution on the installer's host fires at module load.
Affected packages
Package
Name: bnpl-blocks-desktop-bnpl-feedback
Purl: pkg:npm/bnpl-blocks-desktop-bnpl-feedback
Affected ranges
Type: N/A
Events:
