VDB
KO

MAL-2026-13285

Malicious code in dolyame-boxy-atom-bnpl-dangerously-html (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (48ce2aa10d245536ed6cfd1903fe1b553eef84d8e949b0bd1b970817b7f13e98) On require of the package, index.js loads _loader.js which reconstructs attacker-controlled hostnames via string-split.join('') to evade scanners (mirrors of the form oob-worker.cf10{0,1,2}-{baf,adf}.workers.dev and DNS TXT fallback domains under wel1.ru such as sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru), selects a platform/arch-specific asset, downloads a binary from one of the anonymous Cloudflare Workers hosts (with a DNS-over-TXT fallback that base64-reassembles bytes from <n>.<domain> TXT records), writes it to /var/tmp/.cache_<rand> on Unix or %TEMP%\dotnet_diag_<rand>.exe on Windows, chmod 0755, and spawns it detached via /bin/sh -c or cmd.exe. A marker file named.analytics_state and comments referring to 'opt-out environment variables' present a telemetry cover story. There is no hash or signature verification on the downloaded bytes, the destinations are anonymous hosts unrelated to any legitimate publisher, and the package name itself is a lookalike combining unrelated brand/technology tokens.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-boxy-atom-bnpl-dangerously-html

No fixed version published yet for dolyame-boxy-atom-bnpl-dangerously-html (npm). Pin to a known-safe version or switch to an alternative.

References