VDB
KO

MAL-2026-13323

Malicious code in dolyame-boxy-independent-bnpl-origination (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (0512db79eba207153d2427271566e3ecd016d3d817266e683a801d82183254e9) On require, index.js loads _ext.js which detects platform, constructs C2 hostnames by joining split string fragments (e.g. "oob-worker.cf99-9b3.worker" + "s.dev"), downloads an opaque binary from hardcoded Cloudflare Workers endpoints (oob-worker.cf99-9b3.workers.dev, cf101-adf, cf102-baf, cf103-070.workers.dev) with a DNS-TXT covert-channel fallback (base64 chunks reassembled from resolveTxt of numeric subdomains under dl.wel1.ru), writes the payload to a disguised path under /tmp or %TEMP% (.cache_<hex>, dotnet_diag_<hex>.exe), chmods 0755 on Unix, and spawns it detached via /bin/sh or cmd.exe. A state file throttles re-runs. Package name resembles a legitimate BNPL/payment integration but the shipped code implements a remote-payload dropper with no relation to that stated purpose.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-boxy-independent-bnpl-origination

No fixed version published yet for dolyame-boxy-independent-bnpl-origination (npm). Pin to a known-safe version or switch to an alternative.

References