MAL-2026-13296
Malicious code in dolyame-boxy-atom-desktop-bnpl-text (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5b63e38f9a4be0ffccf426124ce23e7d5c0ddfde68cc81ad44cbfe75ef22c31c) The package's index.js silently loads _loader.js via a swallowed try/catch (`try { require('./_loader'); } catch (_) {}`). _loader.js assembles one of three Cloudflare Workers hostnames via array-join string-splitting (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev) and a DNS-TXT fallback under *.dl.wel1.ru, downloads a platform-specific binary, writes it to /tmp or %TEMP% under a disguised name (.cache_<rnd> on Unix, dotnet_diag_<rnd>.exe on Windows), chmods it 0755, and spawns it detached via /bin/sh -c or cmd. The exported class is a no-op shell; the package ships no functionality matching its advertised BNPL/React-component identity. Destination hostnames and the DNS-TXT covert channel (numbered TXT chunk reassembly of base64 payload) are obfuscated to evade static detection.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-atom-desktop-bnpl-text (npm). Pin to a known-safe version or switch to an alternative.