{"schema_version":"1.8.0","id":"MAL-2026-12951","published":"2026-08-05T14:45:17Z","modified":"2026-08-05T15:51:13.285200530Z","summary":"Malicious code in bnpl-blocks-independent-bnpl-button (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7749e7f4c01551d7ec3463d1b65e3f564a9ec64cbc4801586a72652ab55e4e34)\nOn require of the package main, _runtime.js selects a per-OS endpoint, fetches an opaque executable from obfuscated Cloudflare Workers hosts (hostnames assembled by string-splitting, e.g. 'oob-worker.cf100-416.workers.dev') with a DNS-TXT base64-chunked fallback via *.dl.wel1.ru, writes the payload to /var/tmp or the Windows temp directory under disguised names such as 'dotnet_diag_<hex>.exe' and '.cache_<hex>', chmods it to 0755, and detach-spawns it via cp.spawn('/bin/sh', ['-c', <path>+' &'], {detached:true}).unref() or spawn('cmd',...). A second dropper module, lib/telemetry.js, is shipped alongside and implements the same base64-chunked payload -> writeFile -> chmodSync -> '/bin/sh -c <path> &' pattern, with obfuscated identifiers such as require('child_'+'process') and fs['chmod'+'Sync']. Hostname reconstruction via array joins, a no-op logger that suppresses output, disguised filenames, DNS-TXT covert-channel fallback, and detached execution are consistent with an install/load-time remote code execution dropper.\n","affected":[{"package":{"name":"bnpl-blocks-independent-bnpl-button","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-independent-bnpl-button"},"versions":["35.2.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_runtime.js","sha256":"764ad4d58ed1f745412071afabdbef34fa688544b38f31e00c2f67b3269295cd","tlsh":"0ab1b76a06a670084b70d7e4c6175416f666f6633780c198f7ac69881ff712483f2efc"},{"path":"lib/telemetry.js","sha256":"e3eb06400ac6b52c39db91b261bee252e2c28102bdfaba70b070b725dc8e26fa","tlsh":"de835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"bnpl-blocks-independent-bnpl-button-35.2.2.tgz","hashes":{"sha1":"1b41bdd8cc3d1007a430c87a859ef64fa7e5c9cd","sha512_sri":"sha512-fRZM2PH2ZeyIuO6/k9mY8V2Nw8i2/s8kG82WKnOEUcZ6RTgeiPkbbmdKvW+6xk1iUghh9b8MzmSqrhZ9aNZiow=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-independent-bnpl-button/MAL-2026-12951.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-independent-bnpl-button/v/35.2.2"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015428","import_time":"2026-08-05T15:19:50.887017403Z","modified_time":"2026-08-05T14:45:17Z","sha256":"7749e7f4c01551d7ec3463d1b65e3f564a9ec64cbc4801586a72652ab55e4e34","source":"amazon-inspector","versions":["35.2.2"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}