{"id":"MAL-2026-13042","summary":"Malicious code in boxy-esm-shims (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c8f8bbecdfed31ec416782f6de127cb1003692978560504d748acd121b30fa3b)\nOn require() of the package, index.js loads _vendor.js which fetches an opaque binary from string-obfuscated Cloudflare Workers hosts (oob-worker.cf103-07.0.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev) with a DNS-TXT base64 fallback under *.wel1.ru (sdk.dl.wel1.ru). The downloaded bytes are written to /var/tmp or %TEMP% under a disguised name (.cache_\u003chex\u003e on Unix, dotnet_diag_\u003chex\u003e.exe on Windows), chmodded 0755, and spawned detached via /bin/sh -c or cmd.exe with unref(). Destination hostnames and the child_process require are assembled from split string fragments via Array.join to evade static matching, and the fetch is framed as telemetry with cover-story opt-out env vars (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK). A TTL stamp file suppresses repeat execution.\n","modified":"2026-08-05T15:51:55.543582429Z","published":"2026-08-05T14:31:59Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.5.5"],"id":"IN-MAL-2026-015338","import_time":"2026-08-05T15:19:45.625781492Z","modified_time":"2026-08-05T14:31:59Z","sha256":"c8f8bbecdfed31ec416782f6de127cb1003692978560504d748acd121b30fa3b"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-esm-shims/v/35.5.5"}],"affected":[{"package":{"name":"boxy-esm-shims","ecosystem":"npm","purl":"pkg:npm/boxy-esm-shims"},"versions":["35.5.5"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"03b1b85a166970188bb0ebe4c7175416f666f6633380c698fb9c55d41fb2124c3b2efc","path":"_vendor.js","sha256":"ca6331e5438ae6eb0538e339e031bed52c19145d42828f5dce898757e71b835b"}],"package_integrity":[{"filename":"boxy-esm-shims-35.5.5.tgz","hashes":{"sha512_sri":"sha512-zSQ3QKqloavh42Ql3VQMcCY1sK/pFJdztBMUuRPDpLpLhZIMKaF5Z4vGYhvHLiBtAjwlapz8g3eBwXF2ctR2eA==","sha1":"5bc5ac11150d06a72552fc97dffdd10440386d9a"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-esm-shims/MAL-2026-13042.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}