MAL-2026-13307
Malicious code in dolyame-boxy-desktop-bnpl-picture-gallery (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (1ac9b6ff477d28984f8498e58ccc09c6addc4ecce2816fd46f25e5b4cfca49dc) On require of this package, index.js loads _bridge.js which auto-executes an init routine that fetches a platform-specific binary from runtime-assembled Cloudflare Workers hosts (assembled from split fragments joined with.join('') to hide the destination, resolving to oob-worker.cf10x-*.workers.dev). The binary is written under /var/tmp or %TEMP% with disguised names such as dotnet_diag_<rand>.exe or.cache_<rand>, chmod 0755, and spawned detached via /bin/sh -c or cmd.exe. A DNS-TXT fallback channel under *.dl.wel1.ru (resolver domains also assembled from split fragments) reads a count from c.<domain> TXT and iterates <n>.<domain> TXT records, base64-decoding the concatenation into an alternate payload delivery resilient to HTTP egress filtering. Destination hosts and resolver domains are obfuscated via string-split concatenation.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-boxy-desktop-bnpl-picture-gallery (npm). Pin to a known-safe version or switch to an alternative.