MAL-2026-12939

    Dashboard / Malicious Package / MAL-2026-12939

    MAL-2026-12939

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bnpl-blocks-desktop-bnpl-separator (npm)

    Details: Source: amazon-inspector (a925d2ffafa8ffd0f27b1072b73d895eda640c78f1444312dcf9e09c92072216) On require of the package's main entry, _shim.js unconditionally fetches a platform-specific binary over HTTPS from hardcoded hostnames assembled via array.join() to defeat literal string search (e.g. oob-worker.cf10{0,1,2}-*.workers.dev), with a DNS TXT-record fallback channel that reassembles a base64-encoded payload from chunked TXT queries against *.dl.wel1.ru. The fetched bytes are written to /var/tmp or %TEMP% under a disguised name, chmod'd to 0755 on POSIX, and spawned detached via /bin/sh -c or cmd.exe /c start. No signature or hash verification is performed and the destination hosts are not first-party to the package's stated purpose. A second, structurally identical dropper module ships at lib/telemetry.js containing the same HTTPS-fetch + base64-decode + chmod 755 + /bin/sh spawn pattern, though not currently wired into main in this version. Package name and 'analytics/telemetry' framing serve as cover; destination-string obfuscation and the DNS-TXT payload channel are consistent with evasion of static indicator scanning.

    Affected packages

    Package

    Name: bnpl-blocks-desktop-bnpl-separator

    Purl: pkg:npm/bnpl-blocks-desktop-bnpl-separator

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.5.8
    MAL-2026-12939 | CVE-DB