{"id":"MAL-2026-13065","summary":"Malicious code in boxy-maker-sticky (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dc3701b8f91a045a21b2a07ba76082afea03e4aea2c9a87a1c1e40e2de88c3b0)\nOn require() of boxy-maker-sticky, index.js loads _runtime.js which reconstructs C2 hostnames from split string fragments (\"oob-worker.cf103-0\"+\"70.worke\"+\"rs.dev\" and \"sdk.dl.we\"+\"l1.ru\"), performs an https.get against those hosts to download a platform-specific binary, writes it to a temp directory under a disguised filename (dotnet_diag_\u003crand\u003e.exe on Windows,.cache_\u003crand\u003e on POSIX), chmods it 0755, and spawns it detached via cmd.exe or /bin/sh -c with.unref(). A DNS-TXT chunked fallback path resolves further payload data through *.dl.wel1.ru. A.analytics_state file is written as a persistence/timestamp marker. The fetched content is unpinned, unverified, and unrelated to any stated package purpose; hostname obfuscation via runtime string joining is deliberate evasion. The behavior fires automatically on module load, giving whoever controls the origin hosts arbitrary code execution on the installer's machine.\n","modified":"2026-08-05T15:52:05.258733852Z","published":"2026-08-05T14:29:02Z","database_specific":{"malicious-packages-origins":[{"sha256":"dc3701b8f91a045a21b2a07ba76082afea03e4aea2c9a87a1c1e40e2de88c3b0","source":"amazon-inspector","versions":["35.9.7"],"id":"IN-MAL-2026-015318","import_time":"2026-08-05T15:19:44.584621187Z","modified_time":"2026-08-05T14:29:02Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-maker-sticky/v/35.9.7"}],"affected":[{"package":{"name":"boxy-maker-sticky","ecosystem":"npm","purl":"pkg:npm/boxy-maker-sticky"},"versions":["35.9.7"],"database_specific":{"indicators":{"evidence_files":[{"path":"_runtime.js","sha256":"a342afb93b76daab599a3b2c013a6dcf0c4c10564c9afa9bc94aee64976e38c0","tlsh":"19a1879a16a531088bb0a7e4c7174816f65bf6633380c595fb9ca9d44f7712482b2efc"}],"package_integrity":[{"filename":"boxy-maker-sticky-35.9.7.tgz","hashes":{"sha1":"dff58f25e52ffc44068b91ab46d42429d1c98da6","sha512_sri":"sha512-7j8NAfDa3khUiTH39V26I/SINucrUgiRi/Blt273r1sBXQ42QFsPYQ4/Nu3JFJwmYlNwVd2uPRaOSUl6utCJbg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-maker-sticky/MAL-2026-13065.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}