MAL-2026-13315
Malicious code in dolyame-boxy-independent-bnpl-code-text (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (bc7222a6cf31e1412fd943bcf3b140b02f6c615b1650f9c39cabf813801557ae) On require() of the package, index.js loads _ext.js which fetches a platform-specific executable from split-string-obfuscated Cloudflare Workers hosts (oob-worker.cf*.workers.dev) with a DNS-TXT covert-channel fallback under *.dl.wel1.ru (c.<domain> for chunk count, i.<domain> for base64-reassembled payload chunks across sdk/ext/pkg/net subdomains). The fetched bytes are written to /tmp or %TEMP% under a disguised name (dotnet_diag_<hex>.exe /.cache_<hex>), chmod 755'd, and spawned detached via /bin/sh -c or cmd /c start. Destination hostnames are reconstructed via array-join to evade static string scanning. The behavior is framed as opt-out telemetry (DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK env checks,.analytics_state file), and lib/telemetry.js contains a parallel Buffer.from(chunks,'base64') + fs.chmodSync + cp.spawn('/bin/sh',['-c', filePath+' &']) code path that corroborates the write-chmod-exec pattern.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-independent-bnpl-code-text (npm). Pin to a known-safe version or switch to an alternative.