{"id":"MAL-2026-13057","summary":"Malicious code in boxy-maker (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1164ada14e000c3802b5766cdd31ef169e8f15a6d132cbe52d88b0c593b03c2a)\nOn require() of the package, _bridge.js downloads a platform-specific binary from obfuscated Cloudflare workers.dev hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), writes it to a disguised temp path (e.g. dotnet_diag_*.exe,.cache_*), chmods 0755 on non-Windows, and spawns it detached via /bin/sh -c or cmd. Destination hostnames are reassembled at runtime from split-string arrays (e.g. ['oob-worker.cf102','-baf.workers.d','ev'].join('')) to evade static scanners. If HTTPS fetch fails, _bridge.js falls back to a DNS TXT covert channel under wel1.ru subdomains (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), reconstructing chunked base64-encoded payload bytes from TXT records, writing them to disk, and executing them. Cover-story framing (DISABLE_TELEMETRY env var, analytics_state, dotnet_diag_* file names) misrepresents the behavior as CDN telemetry. Installing or importing this package executes attacker-controlled bytes on the host.\n","modified":"2026-08-05T15:52:06.626601941Z","published":"2026-08-05T14:30:28Z","database_specific":{"malicious-packages-origins":[{"versions":["35.4.8"],"id":"IN-MAL-2026-015327","import_time":"2026-08-05T15:19:45.05605929Z","modified_time":"2026-08-05T14:30:28Z","sha256":"1164ada14e000c3802b5766cdd31ef169e8f15a6d132cbe52d88b0c593b03c2a","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-maker/v/35.4.8"}],"affected":[{"package":{"name":"boxy-maker","ecosystem":"npm","purl":"pkg:npm/boxy-maker"},"versions":["35.4.8"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-maker/MAL-2026-13057.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_bridge.js","sha256":"ba39d855ff4e4fc32eae7ccc9c5f9d74e6d1e9160e9e4b1ef09a15e8edd03713","tlsh":"39a1755a12aa301987b0e7e4c717541af65ae6633780c2d4fb9c69841fb726483b1dfc"}],"package_integrity":[{"filename":"boxy-maker-35.4.8.tgz","hashes":{"sha512_sri":"sha512-apDkTrC4ofwWhxDCfBfdPgGxgVv1VSTjA8YQawP1erXcSNCyhRPHOx231oGBKNNzBxNCz4jK0/3ERVT6jVrY0w==","sha1":"69e06ae4f46ff2328098656fd19cbe16839f2faa"}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}