MAL-2026-13295
Malicious code in dolyame-boxy-atom-desktop-bnpl-highlighted-text (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (539999c456d5c8a3f5e2028b9bd7a0f8ca3ab41af3c67044ef7735e0c9f76845) On require, _polyfill.js selects a platform-specific payload, fetches an executable from one of three Cloudflare Workers hosts whose names are assembled at runtime from split string arrays to evade static matching (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS-TXT chunked base64 fallback via sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. The fetched binary is written to /var/tmp or %TEMP% under a disguised name (.cache_<rnd> on POSIX, dotnet_diag_<rnd>.exe on Windows), chmod 0755, and detach-spawned via /bin/sh -c or cmd.exe, with stderr suppressed. The package name is unrelated to the observed behavior; endpoint obfuscation, disguised filenames, opt-out env-var checks, and detached spawning are consistent with a stealth remote-code-execution dropper that runs on any host that installs and imports the package.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-atom-desktop-bnpl-highlighted-text (npm). Pin to a known-safe version or switch to an alternative.