Malicious code in dolyame-boxy-desktop-bnpl-text-block (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (c8c756707c26d481934a28ab399aa9cb9db769f3785006b83a97f519ca90f241) On require(), index.js loads./_platform.js, which assembles OS-specific download URLs from fragmented string pieces pointing at Cloudflare Workers subdomains (oob-worker.cf*-*.workers.dev), fetches an opaque platform-specific binary via https.get, writes it to /var/tmp or %TEMP% under disguised names (.cache_<hex>, dotnet_diag_<hex>.exe), chmods 0755, and spawns it detached via /bin/sh -c '<path> &' on Unix or cmd.exe /c start /b on Windows. A DNS TXT-record fallback (c.<domain> gives chunk count, N.<domain> gives base64 chunks reassembled from hosts like sdk.dl.wel1.ru) provides a covert retrieval channel when HTTPS is blocked. No hash or signature verification is performed; destination hosts are not associated with the package's publisher; hostnames are assembled at runtime specifically to defeat static analysis. Merely importing the package causes a remote binary to be executed on the installer's host.
Malicious code in dolyame-boxy-desktop-bnpl-text-block (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (c8c756707c26d481934a28ab399aa9cb9db769f3785006b83a97f519ca90f241) On require(), index.js loads./_platform.js, which assembles OS-specific download URLs from fragmented string pieces pointing at Cloudflare Workers subdomains (oob-worker.cf*-*.workers.dev), fetches an opaque platform-specific binary via https.get, writes it to /var/tmp or %TEMP% under disguised names (.cache_<hex>, dotnet_diag_<hex>.exe), chmods 0755, and spawns it detached via /bin/sh -c '<path> &' on Unix or cmd.exe /c start /b on Windows. A DNS TXT-record fallback (c.<domain> gives chunk count, N.<domain> gives base64 chunks reassembled from hosts like sdk.dl.wel1.ru) provides a covert retrieval channel when HTTPS is blocked. No hash or signature verification is performed; destination hosts are not associated with the package's publisher; hostnames are assembled at runtime specifically to defeat static analysis. Merely importing the package causes a remote binary to be executed on the installer's host.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13309
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a738530bf8831d5394f06a0
Added to database: 08/05/2026, 18:47:12 UTC
Last updated: 08/05/2026, 18:47:12 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.