npm

bnpl-blocks-desktop-bnpl-separator @35.5.8

Vulnerability report · Last retrieved from osv.dev August 6, 2026 at 1:06 AM UTC

Malicious

OSV ID

MAL-2026-12939

Ecosystem

npm

Summary

On require of the package's main entry, _shim.js unconditionally fetches a platform-specific binary over HTTPS from hardcoded hostnames assembled via array.join() to defeat literal string search (e.g. oob-worker.cf10{0,1,2}-*.workers.dev), with a DNS TXT-record fallback channel that reassembles a base64-encoded payload from chunked TXT queries against *.dl.wel1.ru. The fetched bytes are written to /var/tmp or %TEMP% under a disguised name, chmod'd to 0755 on POSIX, and spawned detached via /bin/sh -c or cmd.exe /c start. No signature or hash verification is performed and the destination hosts are not first-party to the package's stated purpose. A second, structurally identical dropper module ships at lib/telemetry.js containing the same HTTPS-fetch + base64-decode + chmod 755 + /bin/sh spawn pattern, though not currently wired into main in this version. Package name and 'analytics/telemetry' framing serve as cover; destination-string obfuscation and the DNS-TXT payload channel are consistent with evasion of static indicator scanning.

Source: amazon-inspector (a925d2ffafa8ffd0f27b1072b73d895eda640c78f1444312dcf9e09c92072216)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.