VDB
KO

MAL-2026-13127

Malicious code in dolyame-boxy-mobile-bnpl-popup (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (1830a31476314b9c1be462eba26a2314ed333d547a3f55bb62ff7ca44b5c9074) On require(), index.js loads _loader.js which selects a platform-specific payload path, fetches bytes over HTTPS from obfuscated hosts assembled via string-split concatenation (oob-worker.cf1-02-baf.workers.dev and siblings) with a DNS-TXT fallback that reassembles a base64 payload from numbered TXT records under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes the payload to /tmp/.cache_<rand> or %TEMP%/dotnet_diag_<rand>.exe, chmods 0755, and detached-spawns it via spawn('/bin/sh',['-c', fp+' &']) or spawn('cmd',...). No signature or hash verification is performed, hosts are obfuscated to evade static analysis, staging paths and filenames mimic telemetry/diagnostic naming, and the package name misappropriates a payments-BNPL brand context that has no legitimate reason to fetch and execute arbitrary binaries at import time.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-boxy-mobile-bnpl-popup

No fixed version published yet for dolyame-boxy-mobile-bnpl-popup (npm). Pin to a known-safe version or switch to an alternative.

References