Logo
npm

bnpl-blocks-independent-bnpl-search@20.2.9

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 1:37 AM UTC

Malicious

OSV ID

MAL-2026-12341

Ecosystem

npm

Summary

On require of the package, index.js loads _runtime.js which downloads a platform-specific binary from runtime-assembled *.workers.dev hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev), writes it under /tmp or %TEMP% with a disguised name, chmods 0755 on POSIX, and spawns it detached via /bin/sh -c or cmd /c start. Destination hostnames are assembled from split string fragments joined at runtime to evade static URL scanners. When HTTPS fetches fail, the loader falls back to base64-encoded chunks retrieved from DNS TXT records under attacker-controlled subdomains of dl.well1.site (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site), reassembling and executing the payload from the encoded chunks. A second file lib/telemetry.js shipped in the tarball contains a matching download-decode-chmod-spawn class with the same operator shape.

Source: amazon-inspector (e70389e1435e74337e9c402d824a2e90eeb0b2e9f82fc670035973a18382c558)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.