MAL-2026-12922
Dashboard / Malicious Package / MAL-2026-12922
MAL-2026-12922
Summary: Malicious code in bnpl-blocks-desktop-bnpl-floating-button (npm)
Details: Source: amazon-inspector (475a5832e13fe3f55a82c47aace786100dd62ae9c5c5d31e7408ac59930cc917) On require() of the package, index.js loads _helpers.js which downloads a platform-specific binary from Cloudflare Workers hosts whose domain strings are reassembled at runtime via Array.join (e.g. oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev), with a DNS-TXT fallback channel to *.dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru). The fetched bytes are written to /tmp or %TEMP% under deceptive names (.cache_<hex> on POSIX, dotnet_diag_<hex>.exe on Windows), chmod 0755, and spawned detached via /bin/sh -c "<path> &" or cmd.exe /c start /b. A '.analytics_state' marker file and 'telemetry'/'dotnet_diag' naming are used as cover. There is no hash or signature verification, the payload URL is unpinned and mutable, and the harm fires automatically on module load.
Affected packages
Package
Name: bnpl-blocks-desktop-bnpl-floating-button
Purl: pkg:npm/bnpl-blocks-desktop-bnpl-floating-button
Affected ranges
Type: N/A
Events:
