MAL-2026-12931

    Dashboard / Malicious Package / MAL-2026-12931

    MAL-2026-12931

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bnpl-blocks-desktop-bnpl-link-group (npm)

    Details: Source: amazon-inspector (3419412ce27e6f0442a6e828cf62c4f8851be28a969e977a799559e038c75ea7) On require of the package's main entry, index.js loads./_vendor, which reconstructs Cloudflare Workers hostnames (oob-worker.cf102-baf.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev) via runtime string concatenation, downloads platform-specific binary bytes, writes them to a disguised temp filename (.cache_<hex> or dotnet_diag_<hex>.exe), chmods the file to 0755, and spawns it detached via /bin/sh -c '<path> &' on Unix or cmd.exe /c start /b on Windows. A DNS-based fallback discovery mechanism reassembles the domains sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru from split fragments. No hash or signature verification is performed on the downloaded payload, and the destinations are unrelated to any legitimate publisher of this package. A second copy of the dropper primitives (base64 chunk assembly, chmodSync to 0755, detached /bin/sh spawn, string-split require("child_"+"process")) is bundled in lib/telemetry.js. Cover-story comments frame the behavior as analytics/telemetry and cache validation.

    Affected packages

    Package

    Name: bnpl-blocks-desktop-bnpl-link-group

    Purl: pkg:npm/bnpl-blocks-desktop-bnpl-link-group

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.4.1
    MAL-2026-12931 | CVE-DB