VDB
EN

MAL-2026-13306

Malicious code in dolyame-boxy-desktop-bnpl-image-plus-text (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (4501ea4e0c044573a1d76bf04ee806de26c33bd1dc38f21a2d1f00988a96e656) On require() of this package, index.js loads _compat.js which selects platform-specific endpoints assembled from split string arrays (e.g. oob-worker.cf10-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev) and downloads an opaque binary via https.get. If HTTP fetch fails, a fallback path reassembles a base64 payload from numbered DNS TXT records under *.dl.wel1.ru — a covert channel designed to bypass HTTP egress controls. The fetched bytes are written to /var/tmp or %TEMP% under a disguised name (.cache_XXXX on POSIX, dotnet_diag_XXXX.exe on Windows), chmod'd 0755, and spawned detached via /bin/sh -c or cmd.exe. A second module lib/telemetry.js (81KB) bundled in the tarball mirrors the same fetch/chmod/spawn chain using string-concatenation obfuscation of 'child_' + 'process' and 'chmod' + 'Sync', framed as an Analytics SDK; it is not reached from index.js in this version but is a one-line change from activation. The package name presents as a Dolyame BNPL desktop UI component, unrelated to the observed dropper behavior. No hash verification, no publisher pinning, and hostname obfuscation together characterize this as a lure package delivering attacker-controlled code to the installer's host at require() time.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / dolyame-boxy-desktop-bnpl-image-plus-text

No fixed version published yet for dolyame-boxy-desktop-bnpl-image-plus-text (npm). Pin to a known-safe version or switch to an alternative.

참고