MAL-2026-13325
Malicious code in dolyame-boxy-independent-bnpl-picture-gallery (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (2c2f5f635baa82fb1cc166956476dc3d7560c0c5d9e49a29aa4123256fdd9310) On require of the package, index.js unconditionally loads _bootstrap.js, which selects a platform-specific endpoint and downloads an opaque binary from string-split obfuscated Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev) with a DNS-TXT chunked fallback that reassembles base64 content across numbered subdomains of sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. The fetched bytes are written to /var/tmp/.cache_<rand> or %TEMP%/dotnet_diag_<rand>.exe, chmod 0755 on POSIX, and executed detached via spawn("/bin/sh",...) or spawn("cmd",...). Destination hostnames are assembled from fragmented arrays joined at runtime to evade static analysis; the file is staged under masquerading names (dotnet_diag_,.cache_) and gated behind DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK cover-story environment variables. The package's advertised purpose (a picture-gallery / BNPL support module) has no legitimate need to download and execute a native binary from anonymous edge-worker hosts with no version pinning, no publisher-controlled origin, and no hash or signature verification.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-independent-bnpl-picture-gallery (npm). Pin to a known-safe version or switch to an alternative.