{"id":"MAL-2026-13039","summary":"Malicious code in boxy-devtools (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (44d0a7cd9dacffcb1188a7f6dfdde918d6ef5ba334e773f44330c93f4dd38ddf)\nOn require() of the package, index.js unconditionally loads _runtime.js, which fetches an OS-specific binary from attacker-controlled hosts under oob-worker.cf1{00-03}-*.workers.dev (with a DNS TXT chunked-base64 fallback via *.dl.wel1.ru), writes it to /tmp or %TEMP% under a hidden/system-lookalike name, chmods it 0755, and spawns it detached via /bin/sh -c or cmd /c start. Destination hostnames are assembled at runtime from split string arrays (e.g. [\"oob-worker.cf100-416.wor\",\"ker\",\"s.de\",\"v\"].join(\"\") and ['sdk.dl.wel','1.ru'].join(\"\")) to defeat static matching, and environment gates (DISABLE_TELEMETRY, DO_NOT_TRACK, globalThis.__ANALYTICS_SKIP) plus a /tmp/.analytics_state mtime dedup stamp cloak the behavior. The exported BoxyDevtools class is a no-op stub; the sole runtime effect on import is invoking the dropper. Package name and metadata are consistent with a typosquat/impersonation shell around the payload.\n","modified":"2026-08-05T15:51:54.834456587Z","published":"2026-08-05T14:32:31Z","database_specific":{"malicious-packages-origins":[{"versions":["35.9.5"],"id":"IN-MAL-2026-015342","import_time":"2026-08-05T15:19:45.888811279Z","modified_time":"2026-08-05T14:32:31Z","sha256":"44d0a7cd9dacffcb1188a7f6dfdde918d6ef5ba334e773f44330c93f4dd38ddf","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-devtools/v/35.9.5"}],"affected":[{"package":{"name":"boxy-devtools","ecosystem":"npm","purl":"pkg:npm/boxy-devtools"},"versions":["35.9.5"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-devtools/MAL-2026-13039.json","indicators":{"evidence_files":[{"path":"_runtime.js","sha256":"0a7425950c7635936cf5d4298b16272d9b26adde07c81569e94bfb011dc6e7fe","tlsh":"2eb1869a06aab0194bb0d7e4c71b8826f65bfa6337c1c284fb5c95984f721248371dfc"},{"tlsh":"09f0b18555dae45386b093f7df624481f552c8664a475158bd8850fe0ee441442ecf76","path":"index.js","sha256":"5807f871a484b5f308e74903273eeba85ea4bac8c3cd1f46025c1ec7f6a114c8"}],"package_integrity":[{"filename":"boxy-devtools-35.9.5.tgz","hashes":{"sha1":"b67ce283dc67c494c9b798b130bf18b1daf65d16","sha512_sri":"sha512-uzbN01N23frXFkd0jXXRDb0aEIpcCrVY/aG03YbiSDHbyV30VPr+Rvo5K5Z/6qS0w5cW/iR44TbpbEf/9UQr0A=="}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}