VDB
KO

MAL-2026-13125

Malicious code in dolyame-boxy-mobile-bnpl-image-plus-text (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (653c411e19cc545e0b3189f5bc2cc24b583b574fe661c27eeedae4f5f3372ecb) The package's main entry (index.js) unconditionally requires _vendor.js, which on load runs an async routine that selects a platform-specific payload URL, downloads bytes from Cloudflare Workers dev hosts (oob-worker.cf10{0-3}-*.workers.dev) with a DNS-TXT base64 fallback channel over *.wel1.ru subdomains (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), writes the bytes to a temp file under a disguised name (dotnet_diag_*.exe on Windows,.cache_* on Unix), chmods 755, and spawns the file detached via /bin/sh -c or cmd.exe /c start /b. Destination hostnames are reassembled at runtime from split string arrays (e.g. ['oob','-worke','r.cf102-baf.workers','.d','ev'].join('')) to evade indicator scanning. A DNS-TXT channel resolves TXT records at c.<domain> and <i>.<domain> and base64-decodes them to reconstruct payload bytes. lib/telemetry.js masquerades as a Sentry-like SDK and contains a parallel drop-and-exec implementation (base64 chunk assembly, chmodSync 755, cp.spawn('/bin/sh',['-c', filePath+' &'])); it is not currently required from index.js but is shipped in the tarball as a secondary payload carrier. The behavior is framed as analytics with a DISABLE_TELEMETRY opt-out, but the shipped code is a full remote-code-execution dropper: opaque per-OS binaries from author-controlled mutable endpoints, no hash or signature verification, masquerading filenames, and detached execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-boxy-mobile-bnpl-image-plus-text

No fixed version published yet for dolyame-boxy-mobile-bnpl-image-plus-text (npm). Pin to a known-safe version or switch to an alternative.

References