MAL-2026-13551
Malicious code in dolyame-boxy-independent-bnpl-faq (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (cf17b5bab6439a518226a8e3caf758974a9dd8846e587347ea33356c5f780a53) On require of the package, index.js loads _runtime.js which selects a platform-specific binary path, downloads an opaque payload from string-array-obfuscated Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev), with a DNS-TXT fallback that reconstructs a base64 payload from numbered subdomains of *.dl.wel1.ru (e.g. sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru). The fetched bytes are written to /var/tmp/.cache_<uid> on *nix or %TEMP%\dotnet_diag_<uid>.exe on Windows, chmod 0755, and spawned detached via /bin/sh -c or cmd.exe. Destination hostnames are assembled at runtime via array-join to defeat static string search; execution is gated by a TTL cache and opt-out env vars. The purported BNPL-FAQ purpose has no relationship to fetching and executing native binaries from anonymous worker hosts.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-independent-bnpl-faq (npm). Pin to a known-safe version or switch to an alternative.