{"id":"MAL-2026-13077","summary":"Malicious code in boxy-render-unwrap (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (26755161d9a2ac85d670783fc7eb67383b08592dbb67899b916d3e521d560420)\nOn require of boxy-render-unwrap, index.js loads _bootstrap.js which selects a platform-specific payload URL from a set of obfuscated mirror hosts assembled at runtime by joining split string arrays (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS TXT chunked-base64 fallback over subdomains under dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru). _bootstrap.js fetches the opaque binary via https.get, writes it to /tmp or %TEMP% under disguised names (dotnet_diag_\u003crnd\u003e.exe on Windows,.cache_\u003crnd\u003e on POSIX), chmods 0o755 on POSIX, and spawns it detached via cp.spawn(\"/bin/sh\", [\"-c\", fp + \" &\"], {detached:true}).unref() or cmd /c start /b on Windows. A stamp file named.analytics_state is written to mimic legitimate telemetry. Merely importing the package causes fetch-and-execute of attacker-controlled native code on the installer's machine.\n","modified":"2026-08-05T15:52:11.544186545Z","published":"2026-08-05T14:28:16Z","database_specific":{"malicious-packages-origins":[{"versions":["35.7.9"],"id":"IN-MAL-2026-015313","import_time":"2026-08-05T15:19:44.259831237Z","modified_time":"2026-08-05T14:28:16Z","sha256":"26755161d9a2ac85d670783fc7eb67383b08592dbb67899b916d3e521d560420","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-render-unwrap/v/35.7.9"}],"affected":[{"package":{"name":"boxy-render-unwrap","ecosystem":"npm","purl":"pkg:npm/boxy-render-unwrap"},"versions":["35.7.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"6aa195aa16a6701c4bb09bf4c7175415f65ae6633380c298f75ca9981fb35288372efc","path":"_bootstrap.js","sha256":"5293eadb2f345988abb868e92aa300d3c675aadb43bbb472a578939a567a95ef"}],"package_integrity":[{"filename":"boxy-render-unwrap-35.7.9.tgz","hashes":{"sha512_sri":"sha512-jVJPZeW9Pmyfu4JAQQXdfZkUZjDFNU1Zn6qGT0c4K0Vlr7Apr7FBBjumnA0WbZ5UlfcVT213T7aYIQuWROdSrQ==","sha1":"9743cd125bca45058bc6c06212179853bb322853"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-render-unwrap/MAL-2026-13077.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}