-= Per source details. Do not edit below this line.=-
Requiring this package triggers init.js, which selects a platform-specific payload URL from string-concat-obfuscated Cloudflare Workers hostnames (oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev) with a DNS-TXT base64 reassembly fallback to sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. The fetched bytes are written to /tmp or the Windows temp directory under disguised names such as dotnetdiag_*.exe and.cache_*, chmod 0755, and spawned detached via /bin/sh -c or cmd.exe /c start /b. Cover-story naming (.analytics_state run-once marker, DISABLETELEMETRY/DONOTTRACK env checks) frames the behavior as analytics. A secondary dropper with the same fetch/writeFile/chmod/spawn shape ships in lib/telemetry.js, using base64-decoded payload chunks and split-string require('child'+'process'). The destinations are non-publisher infrastructure, the payload bytes are opaque, and hostnames plus module names are assembled at runtime to evade static review.
{
"malicious-packages-origins": [
{
"versions": [
"35.3.8"
],
"id": "IN-MAL-2026-015404",
"import_time": "2026-08-05T15:19:49.546084129Z",
"modified_time": "2026-08-05T14:41:52Z",
"source": "amazon-inspector",
"sha256": "a8e34f125883bf487e46fede3b2094978e853711c0688c8712cc5628e929f0ad"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-HxE7ZPPXGBoPGB9fZsaHjZ4xdHo7GAeF1P0HN/UlHgSqT2nHPBQMIPEpKT/h+T93gAv8eeQ+uyXg5y+huqh6ig==",
"sha1": "a318039bb7f0e9fe5622024ebe0482c68501086b"
},
"filename": "bnpl-blocks-independent-bnpl-separator-35.3.8.tgz"
}
],
"evidence_files": [
{
"path": "_init.js",
"tlsh": "eda1875a056670198b70dbe48b278416f56be663338086d4fb9ca9984f7713483b2efc",
"sha256": "74464173b3b8908a13c9bc32404787985868c091d4efee0c09c0ac7056710bf4"
},
{
"path": "lib/telemetry.js",
"tlsh": "6e835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc",
"sha256": "11f27506025646e252a081be7c417cf9994a86f4a20450dd49f085cbeabcb6cd"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-independent-bnpl-separator/MAL-2026-12969.json"