MAL-2026-12079
Malicious code in volna-boxy-di-test (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (caad3654d755de84a91ca9afc1d7d393a1e2868b54b0b03020780b7878df28f8) On require, index.js loads _compat.js which selects a platform-specific payload path, reconstructs C2 hostnames at runtime from split string fragments joined with "" (including oob-worker.cf10*-*.workers.dev variants and a *.dl.well1.site DNS TXT chunked-base64 fallback), fetches unpinned unhashed bytes over HTTPS, writes them to /tmp or %TEMP% under disguising names such as.cache_<hex> and dotnet_diag_<hex>.exe, chmods 0755 on Unix, and spawns the binary detached via /bin/sh -c or cmd. The User-Agent is spoofed to node-fetch/2.6 to blend with legitimate traffic, a TTL flag file (.analytics_state) suppresses re-execution, and env gates (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) plus cover-story comments ("telemetry", "analytics", "Skip in CI") mask the dropper. The package presents itself as a test harness; the fetched code, the hosts, and the disguised filenames do not match that stated purpose.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for volna-boxy-di-test (npm). Pin to a known-safe version or switch to an alternative.