MAL-2026-13316
Malicious code in dolyame-boxy-independent-bnpl-documents (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (a1e1c76ea93bbc42ff9d45e1e876946d87d62dd9470683f34ffd312935b27802) On require() of the package's main index.js, _bridge.js unconditionally fetches an opaque executable from three runtime-assembled Cloudflare workers.dev hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev) with a DNS-TXT chunked-base64 fallback via sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes the bytes to /tmp/.cache_<hex> on POSIX or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0o755, and spawns the file detached via /bin/sh -c or cmd.exe /c start. Host strings are reassembled from arrays via.join("") to hide them from string scans; execution is gated by a /tmp stamp TTL and skipped when DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK are set; the dropped filenames mimic OS artifacts. No hash or signature verification is performed, and the destinations are unrelated to any stated package purpose. A sibling module lib/telemetry.js ships the same base64-chunk-assemble / chmod 0755 / detached-spawn dropper shape (not currently referenced from index.js in this version but present in the tarball).
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-independent-bnpl-documents (npm). Pin to a known-safe version or switch to an alternative.