bnpl-blocks-desktop-bnpl-documents @20.7.2
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12173
Ecosystem
npm
Summary
On require of the package, index.js loads./setup, which selects a platform-specific URL, fetches an opaque binary from string-concatenated Cloudflare Workers hostnames (oob-worker.cf100-416.workers.dev, cf103-070.workers.dev, cf102-baf.workers.dev), writes it to /var/tmp/.cache_<hex> on POSIX or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh or cmd. Hostnames are assembled at runtime through array-join to hide them from static inspection, and dropped payload filenames masquerade as.NET diagnostics artifacts. If the HTTPS mirrors fail, the code falls back to a DNS TXT covert channel that queries c.<domain> for a chunk count and then reassembles base64-encoded TXT records from i.<domain> across *.dl.well1.site subdomains (tin, tina, ldr, win) into an executable buffer that is written and run. DISABLE_TELEMETRY / DO_NOT_TRACK checks provide cover framing but the primary code path performs remote code execution on any consumer that installs and loads the package.
Source: amazon-inspector (a4909f4a2b9f9355cd2cbde2b75f8a5d7d3f4ec6b79ed828fdb9cc18b23107e0)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.