VDB
EN

MAL-2026-13127

Malicious code in dolyame-boxy-mobile-bnpl-popup (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (1830a31476314b9c1be462eba26a2314ed333d547a3f55bb62ff7ca44b5c9074) On require(), index.js loads _loader.js which selects a platform-specific payload path, fetches bytes over HTTPS from obfuscated hosts assembled via string-split concatenation (oob-worker.cf1-02-baf.workers.dev and siblings) with a DNS-TXT fallback that reassembles a base64 payload from numbered TXT records under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes the payload to /tmp/.cache_<rand> or %TEMP%/dotnet_diag_<rand>.exe, chmods 0755, and detached-spawns it via spawn('/bin/sh',['-c', fp+' &']) or spawn('cmd',...). No signature or hash verification is performed, hosts are obfuscated to evade static analysis, staging paths and filenames mimic telemetry/diagnostic naming, and the package name misappropriates a payments-BNPL brand context that has no legitimate reason to fetch and execute arbitrary binaries at import time.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / dolyame-boxy-mobile-bnpl-popup

No fixed version published yet for dolyame-boxy-mobile-bnpl-popup (npm). Pin to a known-safe version or switch to an alternative.

참고