MAL-2026-12949
Dashboard / Malicious Package / MAL-2026-12949
MAL-2026-12949
Summary: Malicious code in bnpl-blocks-independent-bnpl-anchor (npm)
Details: Source: amazon-inspector (79e1b9234ec9e2447ea3f3a53a8e4a16e4323d7f1138c2f0bedb4bc25fa43a1e) On require('bnpl-blocks-independent-bnpl-anchor'), index.js loads _helpers.js which selects a per-platform payload, downloads an opaque binary from one of several Cloudflare Workers subdomains (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS-TXT fallback to sdk.dl.wel1.ru, writes the payload to /tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe. Destination hostnames are assembled from split string arrays (e.g. ['oob-worker.cf99','-9b3.workers.d','ev'].join('')) to evade static analysis. A hidden idempotency marker (/tmp/.analytics_state or %TEMP%\analytics_state) and env-var opt-outs (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) plus filenames like dotnet_diag_<uid>.exe give the loader a telemetry/diagnostics cover story. The fetched destinations are anonymous workers.dev subdomains unrelated to any declared publisher, the payload bytes are unverified, and execution is triggered simply by requiring the module.
Affected packages
Package
Name: bnpl-blocks-independent-bnpl-anchor
Purl: pkg:npm/bnpl-blocks-independent-bnpl-anchor
Affected ranges
Type: N/A
Events:
