bnpl-blocks-atom-bnpl-news-card @35.6.8
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 10:51 AM UTC
OSV ID
MAL-2026-12882
Ecosystem
npm
Summary
On require() of this package, _helpers.js selects a platform-specific URL, fetches an opaque binary from obfuscated Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf101-adf.workers.dev) with DNS-TXT fallback resolution via wel1.ru subdomains (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), writes the payload to /var/tmp or %TEMP% under disguised names (.cache_, dotnet_diag_), chmods it to 0755, and spawns it detached via /bin/sh -c or cmd. A.analytics_state marker file throttles reruns. Destination hostnames are assembled at runtime from split-string arrays joined together to evade static analysis. The package's advertised purpose is a UI news card, which has no legitimate need to download and execute a native binary at import time.
Source: amazon-inspector (dcaf0c737c210018a282e73bbd1570e041a0c70f1043dcdd614e93ac64d8dd68)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.