MAL-2026-13292
Malicious code in dolyame-boxy-atom-container (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (8fb29bd9c1d233b882994262382b5f0b5b21cb2b868c139720d5ec9533ce9301) On require() of the package, index.js loads _helpers.js which invokes setup() at module load. setup() selects a platform-specific payload path (linux/darwin/win32), rotates through obfuscated Cloudflare Workers hostnames (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev), downloads bytes over HTTPS, writes them to /var/tmp/.cache_<rnd> or %TEMP%/dotnet_diag_<rnd>.exe, sets mode 0755, and detaches execution via /bin/sh -c or cmd /c start. A DNS-TXT chunked fallback reassembles a base64 payload from sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru when HTTPS fetch fails. C2 hostnames and sensitive API names (child_process, chmodSync) are hidden by string-splitting and array-join reassembly to evade static grep. A parallel dropper implementation lives in lib/telemetry.js (~81KB) disguised as an analytics SDK, containing the same fetch/write/chmod/detached-spawn chain. The package's declared purpose is reusable UI components; native-binary download and execution from anonymous Cloudflare Workers subdomains has no legitimate role in that scope, no publisher affiliation, and no hash or signature verification.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for dolyame-boxy-atom-container (npm). Pin to a known-safe version or switch to an alternative.