{"id":"MAL-2026-13080","summary":"Malicious code in boxy-search-workspace-substrings (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5e86dee583e9f4fb1f10351062e6b4a9ddb6b4eae29b59677c1e8f4bf04711b6)\nOn require() of the package, index.js silently loads _loader.js (wrapped in an error-swallowing try/catch). _loader.js reconstructs a set of destination hostnames at runtime via array split/join to evade static analysis — resolving to oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev, with a DNS TXT fallback covert channel on {sdk,ext.dl,pkg.dl,net.dl}.wel1.ru. It fetches a platform-specific binary over https.get, writes it to /tmp or %TEMP% under cover-story names (.cache_\u003crand\u003e on unix, dotnet_diag_\u003crand\u003e.exe on Windows, with an.analytics_state marker file), chmods it to 0755, and spawns it detached via /bin/sh -c or cmd.exe so the child survives after the parent process exits. There is no version pinning, no hash or signature verification, and the destinations are not the package's publisher infrastructure. The package's stated purpose is a trivial no-op utility, which is inconsistent with fetching and executing a native binary at import time. Opt-out is gated only on DISABLE_TELEMETRY / DO_NOT_TRACK environment variables, which do not prevent execution in a default install.\n","modified":"2026-08-05T15:52:12.996384090Z","published":"2026-08-05T14:26:21Z","database_specific":{"malicious-packages-origins":[{"versions":["35.8.6"],"id":"IN-MAL-2026-015300","import_time":"2026-08-05T15:19:43.440943105Z","modified_time":"2026-08-05T14:26:21Z","sha256":"5e86dee583e9f4fb1f10351062e6b4a9ddb6b4eae29b59677c1e8f4bf04711b6","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-search-workspace-substrings/v/35.8.6"}],"affected":[{"package":{"name":"boxy-search-workspace-substrings","ecosystem":"npm","purl":"pkg:npm/boxy-search-workspace-substrings"},"versions":["35.8.6"],"database_specific":{"indicators":{"evidence_files":[{"path":"_loader.js","sha256":"c21dc7d408ef11f9bf959689800237d8a45b353e187c403ff96973060440a0b7","tlsh":"78a1956a026570194b70d7e4c6175415f66af6637680c1d4f7aca9881fb3224c3f2eec"}],"package_integrity":[{"filename":"boxy-search-workspace-substrings-35.8.6.tgz","hashes":{"sha512_sri":"sha512-mKGCO8LVwoml8XO9t4ZeW2Gr+spz/YtuJQ8TElINo5B6KkOZI7+MMuYYZ3r/a28dlXUA0HuXIyJ55MdcbVKtwQ==","sha1":"2b92d1245ee6dc7bd8ec788a96ef1d21196ffd65"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-search-workspace-substrings/MAL-2026-13080.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}