Threats Tagged 'mal-2026-12363'
View all threats tagged with 'mal-2026-12363'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-12363'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in dolyame-boxy-atom-bnpl-email-form (npm) 0 The npm package dolyame-boxy-atom-bnpl-email-form version 20.3.3 contains malicious code that side-loads a runtime script to fetch and execute a binary payload from obfuscated Cloudflare Workers hosts. The payload is written to temporary directories with disguised filenames, given executable permissions, and spawned as a detached process. If the primary HTTPS fetch fails, the package uses a covert DNS TXT record channel to reconstruct and execute the payload. The package masquerades as an Analytics SDK with an opt-out telemetry feature, but this does not reflect its actual malicious behavior. There is no version pinning, hash verification, or signature validation, and the payload sources are not affiliated with the package publisher. Join the discussion | GCVE Database | 08/05/2026, 12:26:35 UTC Added: 08/05/2026, 15:31:27 UTC |
Showing 1 to 1 of 1 result