MAL-2026-12973
Dashboard / Malicious Package / MAL-2026-12973
MAL-2026-12973
Summary: Malicious code in bnpl-blocks-independent-bnpl-tiles (npm)
Details: Source: amazon-inspector (56d26dece8e18d84828b36740c2f6b04f29f695b2a0df9c6699b58cc1f83e11a) On require() of this package, index.js loads _adapter.js which selects a platform-specific asset path, reassembles destination hostnames from split character arrays (Cloudflare Workers subdomains oob-worker.cf100-416.workers.dev, cf103-070/cf99-9b3/cf102-baf.workers.dev and.ru fallbacks sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), fetches an opaque binary over HTTPS, writes it to a temp path under a cover-story name (dotnet_diag_<hex>.exe /.cache_<hex>), chmods 0755 on POSIX, and spawns it detached via /bin/sh -c or cmd. A DNS-TXT covert channel fetches a base64-chunked payload via numbered TXT records when HTTPS is blocked. The host strings are split into arrays and rejoined at runtime to defeat static inspection, and no hash or signature verification is performed on the fetched bytes. Import (require/load) of the module triggers the download-and-execute path unconditionally, giving remote code execution on the installer's machine.
Affected packages
Package
Name: bnpl-blocks-independent-bnpl-tiles
Purl: pkg:npm/bnpl-blocks-independent-bnpl-tiles
Affected ranges
Type: N/A
Events:
