MAL-2026-12988
Dashboard / Malicious Package / MAL-2026-12988
MAL-2026-12988
Summary: Malicious code in bnpl-blocks-mobile-bnpl-feedback (npm)
Details: Source: amazon-inspector (28f1214c6f46b90fa1bf81bde9a79c81a5193e84969ef756f50cbf895c49515b) On require of the package, index.js loads _shim.js which selects a platform-specific binary from a list of string-split-obfuscated Cloudflare Workers hosts (reassembled at runtime, e.g. oob-worker.cf99-9b3.workers.dev), with a DNS-TXT chunked-base64 fallback across wel1.ru subdomains (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru; count served at c.<domain>, parts at N.<domain>). The retrieved payload is written to /tmp or %TEMP% under cover names resembling system tooling (dotnet_diag_*.exe,.cache_*), chmodded 0755 on POSIX, and spawned detached via spawn("/bin/sh",["-c", path+" &"],{detached:true}) or spawn("cmd",...) on Windows. The destinations are obfuscated, unrelated to any legitimate publisher, and the executed bytes are attacker-controlled.
Affected packages
Package
Name: bnpl-blocks-mobile-bnpl-feedback
Purl: pkg:npm/bnpl-blocks-mobile-bnpl-feedback
Affected ranges
Type: N/A
Events:
