VDB
KO

MAL-2026-13552

Malicious code in dolyame-boxy-independent-bnpl-main-title (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (7fd169fe81bc68427ce8c3b472cb376e6d3fdad489d07595a8c8f08f894ac154) On require, index.js loads _polyfill.js which reconstructs hostnames from split string fragments (e.g., 'oob-worker.cf99-9b3.wor'+'ke'+'rs.dev') to reach multiple Cloudflare Workers subdomains, downloads an opaque platform-specific binary, writes it to /tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd with stdio ignored. A DNS TXT chunked-transfer fallback under *.dl.wel1.ru reassembles a base64 payload when HTTPS is blocked. Cover-story naming — file _polyfill.js, cache marker analytics_state, Windows payload dotnet_diag_<hex>.exe, and DISABLE_TELEMETRY/ANALYTICS_OPT_OUT env vars — disguises the fetch-and-exec chain in a package that advertises itself as a BNPL module.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-boxy-independent-bnpl-main-title

No fixed version published yet for dolyame-boxy-independent-bnpl-main-title (npm). Pin to a known-safe version or switch to an alternative.

References