MAL-2026-12922

    Dashboard / Malicious Package / MAL-2026-12922

    MAL-2026-12922

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bnpl-blocks-desktop-bnpl-floating-button (npm)

    Details: Source: amazon-inspector (475a5832e13fe3f55a82c47aace786100dd62ae9c5c5d31e7408ac59930cc917) On require() of the package, index.js loads _helpers.js which downloads a platform-specific binary from Cloudflare Workers hosts whose domain strings are reassembled at runtime via Array.join (e.g. oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev), with a DNS-TXT fallback channel to *.dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru). The fetched bytes are written to /tmp or %TEMP% under deceptive names (.cache_<hex> on POSIX, dotnet_diag_<hex>.exe on Windows), chmod 0755, and spawned detached via /bin/sh -c "<path> &" or cmd.exe /c start /b. A '.analytics_state' marker file and 'telemetry'/'dotnet_diag' naming are used as cover. There is no hash or signature verification, the payload URL is unpinned and mutable, and the harm fires automatically on module load.

    Affected packages

    Package

    Name: bnpl-blocks-desktop-bnpl-floating-button

    Purl: pkg:npm/bnpl-blocks-desktop-bnpl-floating-button

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.7.6
    MAL-2026-12922 | CVE-DB