{"id":"MAL-2026-13069","summary":"Malicious code in boxy-mm-advisor (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (32b540f41a9d31185da353531b46adbb4d2bc9bd9b43efb79a4f8e80fbd51f8a)\nOn require of boxy-mm-advisor, index.js loads _init.js which auto-runs init(). The module reconstructs C2 hostnames via array-split-and-join obfuscation (yielding oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, and sdk/ext/pkg/net.dl.wel1.ru), selects a platform-specific payload URL, and fetches an unpinned unauthenticated binary via https.get. On POSIX it writes the bytes to /tmp/.cache_\u003crand\u003e, chmods 0755, and spawns '/bin/sh -c \u003cfile\u003e &' detached; on Windows it writes to %TEMP%/dotnet_diag_\u003crand\u003e.exe (impersonating a Microsoft diagnostic binary) and spawns via cmd.exe /c start /b detached. If HTTPS retrieval fails, dns.resolveTxt is used to read a chunk count from c.\u003cdomain\u003e.dl.wel1.ru and to pull base64 chunks from 0.\u003cdomain\u003e, 1.\u003cdomain\u003e,..., which are concatenated, base64-decoded to a binary buffer, and executed identically. A.analytics_state marker suppresses re-triggering within ~6 hours. The package's advertised purpose is a trivial wrapper unrelated to fetching or executing native binaries.\n","modified":"2026-08-05T15:52:08.134085309Z","published":"2026-08-05T14:27:47Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T14:27:47Z","sha256":"32b540f41a9d31185da353531b46adbb4d2bc9bd9b43efb79a4f8e80fbd51f8a","source":"amazon-inspector","versions":["35.3.2"],"id":"IN-MAL-2026-015310","import_time":"2026-08-05T15:19:44.094781301Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-mm-advisor/v/35.3.2"}],"affected":[{"package":{"name":"boxy-mm-advisor","ecosystem":"npm","purl":"pkg:npm/boxy-mm-advisor"},"versions":["35.3.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-mm-advisor/MAL-2026-13069.json","indicators":{"evidence_files":[{"path":"_init.js","sha256":"99c345f092aae42cbc85d111d6c49dd28b3c0a55c2f0ec351f08c8c250ca4b4c","tlsh":"91a1865a1266701947b097e487275416f65bf6633380c2d8fbaca5984f7712483b2dfc"}],"package_integrity":[{"filename":"boxy-mm-advisor-35.3.2.tgz","hashes":{"sha1":"518df33798cffade9af6e6c8308d68ae1c292e8c","sha512_sri":"sha512-Jz0FhvArEabecc8VP3zhMKTPKkyoJ4pE5AN9cVYN2OayfPDgKt6Uqg71+O6alOqmINoMVkCD3ZWYhloTe7q+0w=="}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}