VDB
KO

MAL-2026-13324

Malicious code in dolyame-boxy-independent-bnpl-partners (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (ffc33c2ab8bb4f548091d802fa40c836d0a2f655bde7efe2a9db2bc0c9f49287) On require of the package, index.js loads _platform.js, which assembles attacker-controlled hostnames via array-split-and-join obfuscation (oob-worker.*.workers.dev variants and sdk/ext/pkg/net.dl.wel1.ru), fetches a platform-specific binary over HTTPS with a DNS-TXT base64 fallback channel, writes it to /var/tmp or %TEMP% under disguised names such as.cache_<hex> or dotnet_diag_<hex>.exe, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe. Cover-story identifiers such as analytics_state and a DISABLE_TELEMETRY opt-out are used to frame the behavior as telemetry. The package name impersonates a Russian BNPL partner integration, and none of the shipped code implements that stated purpose.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-boxy-independent-bnpl-partners

No fixed version published yet for dolyame-boxy-independent-bnpl-partners (npm). Pin to a known-safe version or switch to an alternative.

References