{"id":"MAL-2026-13068","summary":"Malicious code in boxy-mif-tokens (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e4e9fe90e4c6a7334c75fffb7bd07fdeb785a35b9fc2c1a9e5ce74265296d1c7)\nOn require() of this package, index.js loads _bridge.js which downloads a platform-specific native executable from string-split obfuscated Cloudflare Workers hostnames (reassembled at runtime via [\"...\",\"...\"].join(\"\")) with a DNS TXT-record base64 fallback channel over *.dl.wel1.ru. The fetched bytes are written to /tmp or %TEMP% under decoy names such as.cache_\u003chex\u003e and dotnet_diag_\u003chex\u003e.exe, chmod 0755, and spawned detached via /bin/sh -c '\u003cpath\u003e &' on Unix or cmd /c start /b on Windows, using child_process.spawn(...).unref(). The package presents itself as a token SDK and has no legitimate need to fetch and execute an unpinned, unhashed native binary from non-publisher infrastructure. Hostname reassembly, DNS-over-TXT delivery fallback, hidden staging paths, and decoy filenames are evasion characteristics of a dropper, not of a normal SDK download.\n","modified":"2026-08-05T15:52:07.840578701Z","published":"2026-08-05T14:28:23Z","database_specific":{"malicious-packages-origins":[{"versions":["35.7.1"],"id":"IN-MAL-2026-015314","import_time":"2026-08-05T15:19:44.356715221Z","modified_time":"2026-08-05T14:28:23Z","sha256":"e4e9fe90e4c6a7334c75fffb7bd07fdeb785a35b9fc2c1a9e5ce74265296d1c7","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-mif-tokens/v/35.7.1"}],"affected":[{"package":{"name":"boxy-mif-tokens","ecosystem":"npm","purl":"pkg:npm/boxy-mif-tokens"},"versions":["35.7.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-mif-tokens/MAL-2026-13068.json","indicators":{"evidence_files":[{"path":"_bridge.js","sha256":"bc422b8bdf7fadef961630e53697633cfecfbe0acc34c865379094170f76c523","tlsh":"88a1a85602a670184bb0e7e4c71b8816f65bf66337818298f79c55885f7352483b2dfc"}],"package_integrity":[{"hashes":{"sha1":"eb3abcf0dd02ed9c029f3161644819dec82402a7","sha512_sri":"sha512-XnG0VUlCmGGG8SPDGIk/iE07EYmZsNt+TTvH5zHAkO+SdqHuHtQCWlx/en2HIya2ATQFlp5UzMPALI9MYbRjFQ=="},"filename":"boxy-mif-tokens-35.7.1.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}