{"schema_version":"1.8.0","id":"MAL-2026-12888","published":"2026-08-05T14:55:17Z","modified":"2026-08-05T15:50:44.049982833Z","summary":"Malicious code in bnpl-blocks-atom-bnpl-radio (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (73e47adf2b698665ad917ed4a512279a35c56dc9683950843d18f207d91767e2)\nRequiring this package loads _polyfill.js, whose top-level initialization downloads a platform-specific binary from runtime-reassembled hosts oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, and oob-worker.cf100-416.workers.dev, with DNS-TXT fallback to *.dl.wel1.ru. The binary is written to /tmp or %TEMP% under disguised names (.cache_<rnd>, dotnet_diag_<rnd>.exe), chmodded to 0755, and spawned detached via /bin/sh -c or cmd.exe /c start. No hash or signature verification is performed and the destinations have no relation to the package's stated purpose. Destination hostnames, DNS resolver domains, and sensitive API names (child_process, chmodSync) are assembled at runtime from split string fragments to evade static analysis, and a hidden-dot stamp file with cover-story labels ('analytics_state', 'telemetry') plus an EXPIRE_SEC re-run gate is used. A parallel dropper implementation is bundled in lib/telemetry.js using dynamic child_process import, base64 chunk assembly, /bin/sh spawn, and chmodSync 0755, framed as an 'analytics SDK'.\n","affected":[{"package":{"name":"bnpl-blocks-atom-bnpl-radio","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-atom-bnpl-radio"},"versions":["35.4.8"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_polyfill.js","sha256":"21fcb445eb259d7dcc01672996fd89a5078c0d9ab21d3aae08d7f9255d4dccf8","tlsh":"20a1a66a166670184bb09bf4c6174416f65bf6a33381c284fb9c68985f7321483b2efc"},{"path":"lib/telemetry.js","sha256":"5242939c1a837e4e083da33c4909287b2c37a353adfed9ce046827c308104954","tlsh":"99835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"bnpl-blocks-atom-bnpl-radio-35.4.8.tgz","hashes":{"sha1":"ce518327b1e53c6df094a7988e2cbcb98e0ff07d","sha512_sri":"sha512-yUdrYVTnURscl1Cqa3x0DSq6iIAxe7f2xPpn35OvulDWcSyl4e2iDnCKwuRkmoknsoFmJ6kUhp9T8inG2BE8oQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-atom-bnpl-radio/MAL-2026-12888.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-atom-bnpl-radio/v/35.4.8"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015496","import_time":"2026-08-05T15:19:54.530316993Z","modified_time":"2026-08-05T14:55:17Z","sha256":"73e47adf2b698665ad917ed4a512279a35c56dc9683950843d18f207d91767e2","source":"amazon-inspector","versions":["35.4.8"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}