MAL-2026-13332
Malicious code in dolyame-boxy-independent-bnpl-text-block (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (0d558b476b362ab912d18912a13c79e326b5fcdcdbe73b0f292d94aa89ac732d) On require() of the package, index.js loads _runtime.js, which assembles Cloudflare Workers hostnames (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev) and DNS-TXT fallback hosts under dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru) from split-and-joined string fragments to conceal them from static analysis. It fetches a platform-specific executable payload from those hosts, writes it to a randomly-named file in /tmp or %TEMP% with cover-story names (dotnet_diag_<rnd>.exe,.cache_<rnd>,.analytics_state), chmods it 0755 on Unix, and spawns it detached via /bin/sh -c or cmd /c start. The tarball also ships lib/telemetry.js, an ~81KB unreferenced sibling module implementing the same fetch-write-chmod-spawn pattern with base64-reconstructed payload bytes and string-concatenated 'child_'+'process' / 'chmod'+'Sync' references. The package's declared purpose as a BNPL text-block UI helper has no relationship to the observed dropper behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-independent-bnpl-text-block (npm). Pin to a known-safe version or switch to an alternative.