MAL-2026-13319
Malicious code in dolyame-boxy-independent-bnpl-items (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (b31579fb9a360c4781524c5edd9d0e7b84440e7ccd073e09d54afc10678764cf) On require() of this package, index.js loads _compat.js which unconditionally downloads an OS-specific binary from Cloudflare Workers hosts assembled at runtime via string-array join (oob-worker.cf99-9b3.workers.dev, cf100-416.workers.dev, cf102-baf.workers.dev, cf103-070.workers.dev), with a DNS-TXT chunked fallback served under *.dl.wel1.ru (sdk.dl.wel1.ru). The fetched bytes are written to /tmp or %TEMP% under cover-story filenames (analytics_state, dotnet_diag_*.exe,.cache_*), chmod 0755 on POSIX, then spawned detached and unref'd via /bin/sh -c or cmd.exe /c start /b. No hash or signature verification, no relationship to any legitimate publisher, and the hostnames and the child_process require are obfuscated via array.join to defeat static analysis. Package name impersonates a Dolyame BNPL integration but ships no such functionality.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-independent-bnpl-items (npm). Pin to a known-safe version or switch to an alternative.