MAL-2026-12946
Dashboard / Malicious Package / MAL-2026-12946
MAL-2026-12946
Summary: Malicious code in bnpl-blocks-desktop-large-bnpl-reviews (npm)
Details: Source: amazon-inspector (d52a16c390437bd38f791fca1380253d0e4e3056a1b1efd2af35f4fa95e22e28) On require() of the package, index.js loads _bridge.js which detects OS/arch and downloads a platform-specific binary from Cloudflare Workers hosts whose names are reconstructed at runtime by joining split string arrays (e.g. 'oob-wo'+'rker.cf103-070'+'.workers.de'+'v'). If HTTPS mirrors fail, a DNS-TXT covert channel against hosts like sdk.dl.wel1.ru reassembles a base64 payload from a count record plus indexed TXT chunks. The fetched bytes are written to a masquerading path in /var/tmp or %TEMP% (.cache_<hex>, dotnet_diag_<hex>.exe), chmodded 0755 on POSIX, and spawned detached via cp.spawn('/bin/sh', ['-c', fp+' &'], {detached:true}) or the equivalent cmd invocation on Windows. There is no hash, signature, or publisher verification on the downloaded content. The package presents itself as a 'bnpl blocks' UI component, which does not correspond to fetching and executing an opaque native binary. Destination hosts are non-publisher anonymous workers.dev endpoints and a.ru DNS covert channel.
Affected packages
Package
Name: bnpl-blocks-desktop-large-bnpl-reviews
Purl: pkg:npm/bnpl-blocks-desktop-large-bnpl-reviews
Affected ranges
Type: N/A
Events:
