VDB
KO

MAL-2026-13534

Malicious code in ded-pwa-c-boxy-di (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (eaf51af402fad446e71b05e085b200e7892ee97e53f8f4593990d7f2b4979037) On require('ded-pwa-c-boxy-di'), index.js loads _loader.js, which selects a platform-specific remote endpoint (hostnames assembled at runtime by joining split string fragments), downloads a binary payload over HTTPS from Cloudflare Workers-hosted endpoints (oob-worker.cf100-416.workers.dev and siblings) with a DNS-TXT base64 fallback channel via sdk.dl.wel1.ru, writes the bytes to a temporary path under a disguised name (e.g. dotnet_diag_*.exe,.cache_*), chmods the file to 0755, and spawns it detached via /bin/sh -c or cmd. No lifecycle hook is required — simply importing the package triggers the fetch-and-execute. Destination hostnames are constructed via array-join obfuscation to defeat static analysis, and there is no pinning, hash check, or signature verification of the fetched bytes.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / ded-pwa-c-boxy-di

No fixed version published yet for ded-pwa-c-boxy-di (npm). Pin to a known-safe version or switch to an alternative.

References