MAL-2026-13292
Malicious code in dolyame-boxy-atom-container (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (8fb29bd9c1d233b882994262382b5f0b5b21cb2b868c139720d5ec9533ce9301) On require() of the package, index.js loads _helpers.js which invokes setup() at module load. setup() selects a platform-specific payload path (linux/darwin/win32), rotates through obfuscated Cloudflare Workers hostnames (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev), downloads bytes over HTTPS, writes them to /var/tmp/.cache_<rnd> or %TEMP%/dotnet_diag_<rnd>.exe, sets mode 0755, and detaches execution via /bin/sh -c or cmd /c start. A DNS-TXT chunked fallback reassembles a base64 payload from sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru when HTTPS fetch fails. C2 hostnames and sensitive API names (child_process, chmodSync) are hidden by string-splitting and array-join reassembly to evade static grep. A parallel dropper implementation lives in lib/telemetry.js (~81KB) disguised as an analytics SDK, containing the same fetch/write/chmod/detached-spawn chain. The package's declared purpose is reusable UI components; native-binary download and execution from anonymous Cloudflare Workers subdomains has no legitimate role in that scope, no publisher affiliation, and no hash or signature verification.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-atom-container (npm). Pin to a known-safe version or switch to an alternative.