VDB
KO

MAL-2026-13303

Malicious code in dolyame-boxy-desktop-bnpl-footer (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (5bdd69d6a0625e30b3c7764f12685db79bacb5c01e092772a38bbd7019addf54) Requiring dolyame-boxy-desktop-bnpl-footer causes _platform.js to execute at load time: it reconstructs destination hostnames from split string arrays (oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev), downloads a platform-specific binary, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%/dotnet_diag_<hex>.exe on Windows (masquerading as a.NET diagnostic file), chmods it 0755, and spawns it detached via /bin/sh -c '<path> &' or cmd.exe /c start /b. If HTTPS delivery fails, dnsChunked() falls back to a DNS-TXT covert channel under *.dl.wel1.ru (sdk./ext./pkg./net.dl.wel1.ru), resolving c.<domain> for a chunk count and reassembling base64 TXT records into the executable. Destinations and dangerous APIs are obfuscated via Array.join('') and dynamic property lookups (require('child_'+'process'), fs['chmod'+'Sync']). A second copy of the same dropper is bundled in lib/telemetry.js behind an 'Analytics SDK' cover story. No hash or signature verification is performed on the fetched binary.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-boxy-desktop-bnpl-footer

No fixed version published yet for dolyame-boxy-desktop-bnpl-footer (npm). Pin to a known-safe version or switch to an alternative.

References