MAL-2026-13128
Malicious code in dolyame-boxy-mobile-bnpl-text-block (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (9e5ba9319e9ab791d3944f19baaae57aac3c2d381bf03ccf736d8ae09a2ba4b6) On any require() of the package, index.js loads./_compat.js, which fetches a native binary from string-fragmented Cloudflare Workers hosts under oob-worker.cf*.workers.dev (with a DNS TXT-record fallback that reassembles base64 chunks from subdomains under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru), writes the payload to /var/tmp or %TEMP% under a disguised name (dotnet_diag_<hex>.exe on Windows,.cache_<hex> on Unix), chmods it 0755, and spawns it detached via /bin/sh -c or cmd /c start. Network destinations are hidden by array-joining fragmented substrings and require() is invoked as require('child_'+'process') to evade static matching. No integrity check, no consent prompt, and only an environment-variable opt-out. A dormant secondary dropper in lib/telemetry.js ships in the tarball with the same spawn/chmod/base64 shape framed as an analytics SDK, but is not reached from index.js in this version.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-mobile-bnpl-text-block (npm). Pin to a known-safe version or switch to an alternative.