MAL-2026-12984
Dashboard / Malicious Package / MAL-2026-12984
MAL-2026-12984
Summary: Malicious code in bnpl-blocks-mobile-bnpl-category-gallery (npm)
Details: Source: amazon-inspector (c3b498a386a4aeab43aedc022880d8bf90e2d8feb2cc94bafe313fa73c09b4b1) On any require() of this package, index.js loads _loader.js, which reconstructs destination hostnames at runtime from array-join fragments (oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, with DNS-TXT fallbacks under *.dl.wel1.ru), downloads a platform-specific binary from those hosts, writes it to /tmp or %TEMP% under masquerading filenames such as dotnet_diag_*.exe or.cache_*, chmods it 0755, and spawns it detached via cp.spawn("/bin/sh", ["-c", fp+" &"], {detached:true}) or spawn("cmd",...). A second, parallel dropper is bundled in lib/telemetry.js: a base64-decoded payload buffer is written, chmod'd 0755, and executed via detached /bin/sh. child_process and hostname strings are assembled with require("child_"+"process") and [...].join("") to evade static analysis. The opaque remote payload has no hash or signature verification and originates from non-publisher Cloudflare Workers infrastructure.
Affected packages
Package
Name: bnpl-blocks-mobile-bnpl-category-gallery
Purl: pkg:npm/bnpl-blocks-mobile-bnpl-category-gallery
Affected ranges
Type: N/A
Events:
