MAL-2026-12883

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-atom-bnpl-no-index-link/MAL-2026-12883.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12883
Published
2026-08-05T14:55:58Z
Modified
2026-08-05T15:50:41Z
Summary
Malicious code in bnpl-blocks-atom-bnpl-no-index-link (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (02bfd5111a000f3f369e2f973d3717b22e1718fb2edbc4b38a07b67aa395815b)

On require of the package, index.js loads bootstrap.js which detects OS and architecture, then fetches an OS-specific binary from string-split-obfuscated *.workers.dev endpoints (oob-worker.cf101-adf.workers.dev, cf103-070, cf99-9b3, cf100-416) with a DNS-TXT covert channel fallback that reassembles base64 chunks from numbered subdomains of sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The downloaded bytes are written to /var/tmp or %TEMP% under a disguised name (dotnet_diag.exe on Windows,.cache_ on Unix), chmod 0755, and spawned detached via /bin/sh or cmd. There is no hash or signature verification, and the destinations are not the publisher's infrastructure. The behavior is framed with cover-story naming (.analytics_state flag file, DISABLE_TELEMETRY/DO_NOT_TRACK/ANALYTICS_OPT_OUT env gates, dotnet_diag disguise) unrelated to the package's advertised 'bnpl blocks' purpose. Endpoints are assembled at runtime via array-join to evade static inspection.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-015501",
            "import_time": "2026-08-05T15:19:54.834901065Z",
            "modified_time": "2026-08-05T14:55:58Z",
            "sha256": "02bfd5111a000f3f369e2f973d3717b22e1718fb2edbc4b38a07b67aa395815b",
            "source": "amazon-inspector",
            "versions": [
                "35.1.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / bnpl-blocks-atom-bnpl-no-index-link

Package

Name
bnpl-blocks-atom-bnpl-no-index-link
View open source insights on deps.dev
Purl
pkg:npm/bnpl-blocks-atom-bnpl-no-index-link

Affected ranges

Affected versions

35.*
35.1.2

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "_bootstrap.js",
            "sha256": "ce0af129fd77384aeac3318942967732f4ad18e2fe2ffac0fa76252d650f8ea5",
            "tlsh": "6ca1a75a15a6701987b0dbe486174816f65ffa633780c1c8fb9ca9984f76124c2b2efc"
        }
    ],
    "package_integrity": [
        {
            "filename": "bnpl-blocks-atom-bnpl-no-index-link-35.1.2.tgz",
            "hashes": {
                "sha1": "9fb42caad27084b773588fcf948be6a8b3f0d5c7",
                "sha512_sri": "sha512-0A/JeJS5DNBHNZXxXvLMvXCkIYvXizYuHfRAYkTCldsKfTbCcmW9LsTaAcPa2Wz9udFte3dzj3exwKfYzdVdKw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-atom-bnpl-no-index-link/MAL-2026-12883.json"