MAL-2026-13125
Malicious code in dolyame-boxy-mobile-bnpl-image-plus-text (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (653c411e19cc545e0b3189f5bc2cc24b583b574fe661c27eeedae4f5f3372ecb) The package's main entry (index.js) unconditionally requires _vendor.js, which on load runs an async routine that selects a platform-specific payload URL, downloads bytes from Cloudflare Workers dev hosts (oob-worker.cf10{0-3}-*.workers.dev) with a DNS-TXT base64 fallback channel over *.wel1.ru subdomains (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), writes the bytes to a temp file under a disguised name (dotnet_diag_*.exe on Windows,.cache_* on Unix), chmods 755, and spawns the file detached via /bin/sh -c or cmd.exe /c start /b. Destination hostnames are reassembled at runtime from split string arrays (e.g. ['oob','-worke','r.cf102-baf.workers','.d','ev'].join('')) to evade indicator scanning. A DNS-TXT channel resolves TXT records at c.<domain> and <i>.<domain> and base64-decodes them to reconstruct payload bytes. lib/telemetry.js masquerades as a Sentry-like SDK and contains a parallel drop-and-exec implementation (base64 chunk assembly, chmodSync 755, cp.spawn('/bin/sh',['-c', filePath+' &'])); it is not currently required from index.js but is shipped in the tarball as a secondary payload carrier. The behavior is framed as analytics with a DISABLE_TELEMETRY opt-out, but the shipped code is a full remote-code-execution dropper: opaque per-OS binaries from author-controlled mutable endpoints, no hash or signature verification, masquerading filenames, and detached execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-mobile-bnpl-image-plus-text (npm). Pin to a known-safe version or switch to an alternative.