VDB
KO

MAL-2026-13309

Malicious code in dolyame-boxy-desktop-bnpl-text-block (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (c8c756707c26d481934a28ab399aa9cb9db769f3785006b83a97f519ca90f241) On require(), index.js loads./_platform.js, which assembles OS-specific download URLs from fragmented string pieces pointing at Cloudflare Workers subdomains (oob-worker.cf*-*.workers.dev), fetches an opaque platform-specific binary via https.get, writes it to /var/tmp or %TEMP% under disguised names (.cache_<hex>, dotnet_diag_<hex>.exe), chmods 0755, and spawns it detached via /bin/sh -c '<path> &' on Unix or cmd.exe /c start /b on Windows. A DNS TXT-record fallback (c.<domain> gives chunk count, N.<domain> gives base64 chunks reassembled from hosts like sdk.dl.wel1.ru) provides a covert retrieval channel when HTTPS is blocked. No hash or signature verification is performed; destination hosts are not associated with the package's publisher; hostnames are assembled at runtime specifically to defeat static analysis. Merely importing the package causes a remote binary to be executed on the installer's host.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-boxy-desktop-bnpl-text-block

No fixed version published yet for dolyame-boxy-desktop-bnpl-text-block (npm). Pin to a known-safe version or switch to an alternative.

References