{"id":"MAL-2026-13028","summary":"Malicious code in boxy-adapter-tramvai (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d20d5167abc8703b7b09a0d9698e6d0fd060f4378dfa11ab469af3e6805cfc8e)\nOn library load, index.js requires./_runtime.js, which selects a platform-specific staging path, fetches an opaque binary from obfuscated Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS-TXT base64 fallback under *.dl.wel1.ru (sdk/ext/pkg/net subdomains), writes the bytes to /var/tmp/.cache_\u003chex\u003e or %TEMP%\\dotnet_diag_\u003chex\u003e.exe, chmods 0755, and detached-spawns via /bin/sh -c or cmd. Hostnames are reconstructed at runtime via Array.join fragments to evade static analysis; a cache marker file at /tmp/.analytics_state gates re-execution, and env vars named DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK are used as a telemetry cover story. The DNS-TXT channel reads a chunk count from c.\u003cdomain\u003e then reassembles base64 fragments from 0.\u003cdomain\u003e..N.\u003cdomain\u003e into an executable buffer, providing a firewall-evading secondary delivery path. Payload bytes are unpinned, unverified, and staged under filenames impersonating OS diagnostic tools. The name mimics the legitimate @tramvai ecosystem.\n","modified":"2026-08-05T15:51:49.392946395Z","published":"2026-08-05T14:33:54Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015351","import_time":"2026-08-05T15:19:46.489148927Z","modified_time":"2026-08-05T14:33:54Z","sha256":"d20d5167abc8703b7b09a0d9698e6d0fd060f4378dfa11ab469af3e6805cfc8e","source":"amazon-inspector","versions":["35.6.6"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-adapter-tramvai/v/35.6.6"}],"affected":[{"package":{"name":"boxy-adapter-tramvai","ecosystem":"npm","purl":"pkg:npm/boxy-adapter-tramvai"},"versions":["35.6.6"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"d30ddc11055c8b40864a5ba78e5e66394f7ef3a8","sha512_sri":"sha512-JgRwPS79Xjh9Aa1mc1suOeFhSomQnazuyqsHuAoz1kWHFT7IGyaqiFbimVaav+GDyC7VKlpXy44ngwDF21zr4Q=="},"filename":"boxy-adapter-tramvai-35.6.6.tgz"}],"evidence_files":[{"sha256":"860e8ca4e8dc97c1d9368937d9919299196c8fe1778103a0fabb8a540fda9688","tlsh":"d5a1989a16a670194bb09bf4c6174816f65bf6a37380c2c4fb5c69984f7352483b2efc","path":"_runtime.js"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-adapter-tramvai/MAL-2026-13028.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}