MAL-2026-12980

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-mobile-bnpl-breadcrumbs/MAL-2026-12980.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12980
Published
2026-08-05T14:41:59Z
Modified
2026-08-05T15:51:26.282355989Z
Summary
Malicious code in bnpl-blocks-mobile-bnpl-breadcrumbs (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (84017ba181747092b950696fe772d2896affe17dbff25258d2372a4578c7e1cb)

index.js requires./loader on load. loader.js assembles network destinations at runtime by concatenating split string fragments (e.g. ['oob-worker.cf103','-070.worke','rs','.dev'].join('')) to hide endpoints on oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, and oob-worker.cf100-416.workers.dev, and falls back to a DNS-TXT covert delivery channel at *.dl.wel1.ru that reads a chunk count from c.<domain> and reassembles base64 payload chunks from numbered subdomains. The downloaded opaque, unpinned, unverified binary is written to /var/tmp or %TEMP% under cover-story names ('dotnetdiag<hex>.exe', '.cache<hex>', 'analyticsstate'), chmod 0755 on Unix, and spawned detached via /bin/sh -c or cmd.exe. The dropper honors DISABLETELEMETRY / ANALYTICSOPTOUT / DONOT_TRACK environment variables to suppress execution as an anti-analysis measure. The package's stated purpose ('device integration') is unrelated to the fetched executable and no legitimate functionality is shipped.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "84017ba181747092b950696fe772d2896affe17dbff25258d2372a4578c7e1cb",
            "id": "IN-MAL-2026-015405",
            "modified_time": "2026-08-05T14:41:59Z",
            "source": "amazon-inspector",
            "import_time": "2026-08-05T15:19:49.617158869Z",
            "versions": [
                "35.3.4"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / bnpl-blocks-mobile-bnpl-breadcrumbs

Package

Name
bnpl-blocks-mobile-bnpl-breadcrumbs
View open source insights on deps.dev
Purl
pkg:npm/bnpl-blocks-mobile-bnpl-breadcrumbs

Affected ranges

Affected versions

35.*
35.3.4

Database specific

indicators
{
    "evidence_files": [
        {
            "sha256": "b40d4b9f1d6c9f8f48489c6938f00920ace5a56eb54c9850a0353be7cff422c8",
            "path": "_loader.js",
            "tlsh": "07a1839a06aa70098bb0d7e487175426f65be6633380c2c4fb9ca9945f7252483b2dfc"
        }
    ],
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-mdqRV4PQtcTdTX7snchpO46t94zWxAoGmL2f+Eow2Y3pRpxCHue2A4vAuAdtQdzliGiiGURbTU5o2g2iXy+4wA==",
                "sha1": "3afbbbc78b0f0076a51decc16316fa46b5138f9d"
            },
            "filename": "bnpl-blocks-mobile-bnpl-breadcrumbs-35.3.4.tgz"
        }
    ]
}
cwes
[
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-mobile-bnpl-breadcrumbs/MAL-2026-12980.json"