{"id":"MAL-2026-13058","summary":"Malicious code in boxy-maker-bus (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b8e609c87c0dbbf2a870faf3c1e8ea2b322b32d147974f4ec62c400fd026744a)\nboxy-maker-bus@35.7.7 acts as a load-time dropper. The package's index.js unconditionally requires _compat.js on load, which assembles Cloudflare Workers hostnames (oob-worker.cf99-9b3/cf100-416/cf101-adf.workers.dev) and a wel1.ru-based DNS covert channel from split string fragments, downloads a platform-specific opaque binary over HTTPS with no hash or signature verification, writes it to a disguised path (dotnet_diag_\u003ctoken\u003e.exe on Windows,.cache_\u003ctoken\u003e on POSIX) under /tmp or %TEMP%, chmods 0755, and spawns it detached via cmd.exe /c start /b or /bin/sh -c. A secondary delivery path enumerates DNS TXT records at c.\u003cdomain\u003e and \u003ci\u003e.\u003cdomain\u003e, concatenates the chunks, and base64-decodes them into the executable payload. The dropper is wrapped in cover-story naming (analytics_state stamp file, DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK env gates, an unused lib/telemetry.js labeled 'Analytics SDK', dotnet_diag filename) that does not correspond to the package's stated 'runtime support module' purpose. The delivered bytes are attacker-controlled and unverified, giving whoever controls the workers.dev and wel1.ru infrastructure arbitrary code execution on any host that installs or imports the package.\n","modified":"2026-08-05T15:52:02.131763778Z","published":"2026-08-05T14:29:13Z","database_specific":{"malicious-packages-origins":[{"sha256":"b8e609c87c0dbbf2a870faf3c1e8ea2b322b32d147974f4ec62c400fd026744a","source":"amazon-inspector","versions":["35.7.7"],"id":"IN-MAL-2026-015319","import_time":"2026-08-05T15:19:44.637368917Z","modified_time":"2026-08-05T14:29:13Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-maker-bus/v/35.7.7"}],"affected":[{"package":{"name":"boxy-maker-bus","ecosystem":"npm","purl":"pkg:npm/boxy-maker-bus"},"versions":["35.7.7"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-cA5MuJKee3y5QRMdZMm1WBLBEMFHHP8KwJYlTj754mKLy576CULr1yOwXEwQFR5Z5Sp9iQgLAirfQhF2rSV2lQ==","sha1":"1656af5b4499c4941fd7a75be187867b3d23abec"},"filename":"boxy-maker-bus-35.7.7.tgz"}],"evidence_files":[{"path":"_compat.js","sha256":"7414bdd256ebf5ba6be881a3e876b58342b28d88287ecadbd34175154334d383","tlsh":"23b1c59a116670184f70ebe4c61b8815f96af6633781c284fb9c99984fb3514c372efc"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-maker-bus/MAL-2026-13058.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}