MAL-2026-12973

    Dashboard / Malicious Package / MAL-2026-12973

    MAL-2026-12973

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bnpl-blocks-independent-bnpl-tiles (npm)

    Details: Source: amazon-inspector (56d26dece8e18d84828b36740c2f6b04f29f695b2a0df9c6699b58cc1f83e11a) On require() of this package, index.js loads _adapter.js which selects a platform-specific asset path, reassembles destination hostnames from split character arrays (Cloudflare Workers subdomains oob-worker.cf100-416.workers.dev, cf103-070/cf99-9b3/cf102-baf.workers.dev and.ru fallbacks sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), fetches an opaque binary over HTTPS, writes it to a temp path under a cover-story name (dotnet_diag_<hex>.exe /.cache_<hex>), chmods 0755 on POSIX, and spawns it detached via /bin/sh -c or cmd. A DNS-TXT covert channel fetches a base64-chunked payload via numbered TXT records when HTTPS is blocked. The host strings are split into arrays and rejoined at runtime to defeat static inspection, and no hash or signature verification is performed on the fetched bytes. Import (require/load) of the module triggers the download-and-execute path unconditionally, giving remote code execution on the installer's machine.

    Affected packages

    Package

    Name: bnpl-blocks-independent-bnpl-tiles

    Purl: pkg:npm/bnpl-blocks-independent-bnpl-tiles

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.8.9
    MAL-2026-12973 | CVE-DB