MAL-2026-12977
Dashboard / Malicious Package / MAL-2026-12977
MAL-2026-12977
Summary: Malicious code in bnpl-blocks-mobile-bnpl-action-panel (npm)
Details: Source: amazon-inspector (f3362a69d0a3341fff7a48ebdd4a8231ec5a365dc237c62a5b95619fe051e762) On require(), index.js loads _bootstrap.js, which selects a per-platform payload path, fetches a binary over HTTPS from hardcoded hosts assembled by concatenating short string fragments (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS-TXT fallback that reassembles base64 chunks across numbered subdomains of sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The fetched bytes are written to /var/tmp or the Windows TEMP directory under cover-story names (.cache_<hex>, dotnet_diag_<hex>.exe), chmod 0755 on POSIX, then spawned detached via /bin/sh -c or cmd.exe. Host strings and API surface are split across arrays and reassembled via.join("") (e.g. require("child_"+"process"), fs["chmod"+"Sync"]) to evade static analysis. A second dropper module lib/telemetry.js (81 KB) is bundled but not require()d in this version; it mirrors the same DNS discovery, HTTPS+base64 reassembly, chmod, and detached /bin/sh spawn pattern under an "Analytics SDK" framing. Package name and file names impersonate a mobile BNPL UI component and telemetry/analytics tooling; the actual behavior is unverified remote-binary execution on any host that installs or imports the package.
Affected packages
Package
Name: bnpl-blocks-mobile-bnpl-action-panel
Purl: pkg:npm/bnpl-blocks-mobile-bnpl-action-panel
Affected ranges
Type: N/A
Events:
