VDB
KO

MAL-2026-13337

Malicious code in dolyame-boxy-mobile-bnpl-button-set (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (ce4829363e0b5248ca374f2bd545b219d5235bbc96936ba5bd9d06f369878538) On require, index.js loads _shim.js which selects a platform-specific endpoint from a set of runtime-assembled Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS-TXT base64 fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. Hostnames are hidden by splitting across array fragments joined at runtime. _shim.js downloads an opaque binary payload with no hash or signature verification, writes it to /tmp or %TEMP% under decoy filenames (dotnet_diag_<rand>.exe on Windows,.cache_<rand> on Unix), chmods it 0755, and spawns it detached via cmd.exe /c start or /bin/sh -c '<file> &'. A marker file analytics_state/.analytics_state is written, stderr logging is suppressed, and environment opt-outs (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) frame the dropper as telemetry. A dormant 81 KB lib/telemetry.js contains a parallel download-write-chmod-spawn code path with base64 payload reassembly, not currently referenced. The declared purpose of the package (a BNPL button UI component) does not require fetching or executing native binaries.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-boxy-mobile-bnpl-button-set

No fixed version published yet for dolyame-boxy-mobile-bnpl-button-set (npm). Pin to a known-safe version or switch to an alternative.

References