VDB
Sign up

MAL-2026-12989

Malicious code in bnpl-blocks-mobile-bnpl-floating-button (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (be8101254611004c84932cd102d4fb71dc7e692d67696df081e66bd37ba3088b) On require(), index.js loads _support.js whose top-level main() downloads a platform-specific binary from author-controlled hosts assembled via string-array concatenation (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru) with a DNS-TXT base64 fallback. The fetched bytes are written to /tmp or %TEMP% under stealth names such as dotnet_diag_<hex>.exe and.cache_<hex>, chmod'd 0755 on POSIX (with the API name assembled as 'chmod'+'Sync'), and executed detached via /bin/sh -c '<path> &' or cmd /c start /b. A second dropper is shipped in lib/telemetry.js (81KB, framed as an 'Analytics SDK') implementing the same base64-decode + chmod-via-string-concat + detached spawn pattern as an alternate loader. child_process is resolved via require('child_' + 'process') and destination hostnames are split across arrays to evade static analysis. No version pin, no hash or signature verification, and a /tmp stamp file is used for rate-limiting. The package name and metadata claim a mobile BNPL floating-button UI component, which conflicts with the shipped behavior.

## Source: ghsa-malware (a30865fbc89f5c33627deac3092d6d094e14d3e1886c2c38416d61e25933c442) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bnpl-blocks-mobile-bnpl-floating-button
Introduced in: 0

No fixed version published yet for bnpl-blocks-mobile-bnpl-floating-button (npm). Pin to a known-safe version or switch to an alternative.

References