-= Per source details. Do not edit below this line.=-
On require of the package, index.js loads bootstrap.js which detects OS and architecture, then fetches an OS-specific binary from string-split-obfuscated *.workers.dev endpoints (oob-worker.cf101-adf.workers.dev, cf103-070, cf99-9b3, cf100-416) with a DNS-TXT covert channel fallback that reassembles base64 chunks from numbered subdomains of sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The downloaded bytes are written to /var/tmp or %TEMP% under a disguised name (dotnet_diag.exe on Windows,.cache_ on Unix), chmod 0755, and spawned detached via /bin/sh or cmd. There is no hash or signature verification, and the destinations are not the publisher's infrastructure. The behavior is framed with cover-story naming (.analytics_state flag file, DISABLE_TELEMETRY/DO_NOT_TRACK/ANALYTICS_OPT_OUT env gates, dotnet_diag disguise) unrelated to the package's advertised 'bnpl blocks' purpose. Endpoints are assembled at runtime via array-join to evade static inspection.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-015501",
"import_time": "2026-08-05T15:19:54.834901065Z",
"modified_time": "2026-08-05T14:55:58Z",
"sha256": "02bfd5111a000f3f369e2f973d3717b22e1718fb2edbc4b38a07b67aa395815b",
"source": "amazon-inspector",
"versions": [
"35.1.2"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "_bootstrap.js",
"sha256": "ce0af129fd77384aeac3318942967732f4ad18e2fe2ffac0fa76252d650f8ea5",
"tlsh": "6ca1a75a15a6701987b0dbe486174816f65ffa633780c1c8fb9ca9984f76124c2b2efc"
}
],
"package_integrity": [
{
"filename": "bnpl-blocks-atom-bnpl-no-index-link-35.1.2.tgz",
"hashes": {
"sha1": "9fb42caad27084b773588fcf948be6a8b3f0d5c7",
"sha512_sri": "sha512-0A/JeJS5DNBHNZXxXvLMvXCkIYvXizYuHfRAYkTCldsKfTbCcmW9LsTaAcPa2Wz9udFte3dzj3exwKfYzdVdKw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-atom-bnpl-no-index-link/MAL-2026-12883.json"