MAL-2026-12993

    Dashboard / Malicious Package / MAL-2026-12993

    MAL-2026-12993

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bnpl-blocks-mobile-bnpl-image-plus-text (npm)

    Details: Source: amazon-inspector (1fe5dcff2d2c8210499718411ebd66f6810c42a8439728a3919636548598b494) On require of the package, _compat.js assembles remote endpoint hostnames from split string arrays (e.g. oob-worker.cf10x-*.workers.dev) and includes a DNS TXT-record base64 fallback channel over c.<domain> and numbered subdomains of dl.wel1.ru. It downloads a platform-specific binary from those attacker-controlled hosts with no hash or signature verification, writes it to a temp path under a masquerading name (dotnet_diag_*.exe on Windows,.cache_* on Unix), chmods it 0755, and spawns it detached via cmd.exe /c start /b or /bin/sh -c. The dropper runs on module load with a TTL stamp to suppress re-execution. Behaviors observed include platform gating, cover-story naming, string-concatenation obfuscation of the C2 hosts, and a covert DNS TXT-record fallback for endpoint resolution.

    Affected packages

    Package

    Name: bnpl-blocks-mobile-bnpl-image-plus-text

    Purl: pkg:npm/bnpl-blocks-mobile-bnpl-image-plus-text

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.3.2
    MAL-2026-12993 | CVE-DB