VDB
KO

MAL-2026-13128

Malicious code in dolyame-boxy-mobile-bnpl-text-block (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9e5ba9319e9ab791d3944f19baaae57aac3c2d381bf03ccf736d8ae09a2ba4b6) On any require() of the package, index.js loads./_compat.js, which fetches a native binary from string-fragmented Cloudflare Workers hosts under oob-worker.cf*.workers.dev (with a DNS TXT-record fallback that reassembles base64 chunks from subdomains under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru), writes the payload to /var/tmp or %TEMP% under a disguised name (dotnet_diag_<hex>.exe on Windows,.cache_<hex> on Unix), chmods it 0755, and spawns it detached via /bin/sh -c or cmd /c start. Network destinations are hidden by array-joining fragmented substrings and require() is invoked as require('child_'+'process') to evade static matching. No integrity check, no consent prompt, and only an environment-variable opt-out. A dormant secondary dropper in lib/telemetry.js ships in the tarball with the same spawn/chmod/base64 shape framed as an analytics SDK, but is not reached from index.js in this version.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-boxy-mobile-bnpl-text-block

No fixed version published yet for dolyame-boxy-mobile-bnpl-text-block (npm). Pin to a known-safe version or switch to an alternative.

References