{"id":"MAL-2026-13085","summary":"Malicious code in boxy-story-header (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6a1273cea6d0d4cdf432c47fda7e95f529858a1bddefaaeeb976248ea55504f2)\nindex.js unconditionally requires./setup on load. setup.js reconstructs C2 hostnames by array-joining string fragments (Cloudflare Workers subdomains including oob-worker.cf99-9b3.workers.dev) and falls back to a base64-chunked DNS-TXT covert channel under numeric subdomains of wel1.ru. It downloads a platform-specific binary via https.get, writes it to /tmp/.cache_\u003chex\u003e or %TEMP%\\dotnet_diag_\u003chex\u003e.exe under a hidden or system-masquerading name, chmods it 0755, and spawns it detached through /bin/sh -c or cmd.exe /c start /b with no signature or hash verification. lib/telemetry.js reimplements the same fetch-decode-chmod-spawn dropper primitives (Buffer.from(...,'base64'), fs['chmod'+'Sync'](path, mode|0o755), cp.spawn('/bin/sh',['-c',filePath+' &'],{detached:true})). Host obfuscation, DNS-TXT fallback, hidden/masquerading filenames, and unauthenticated remote execution on import satisfy the install-time-rce fingerprint (known-bad-infrastructure dropper).\n","modified":"2026-08-05T15:52:15.599068506Z","published":"2026-08-05T14:24:15Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015286","import_time":"2026-08-05T15:19:42.614558727Z","modified_time":"2026-08-05T14:24:15Z","sha256":"6a1273cea6d0d4cdf432c47fda7e95f529858a1bddefaaeeb976248ea55504f2","source":"amazon-inspector","versions":["35.7.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-story-header/v/35.7.2"}],"affected":[{"package":{"name":"boxy-story-header","ecosystem":"npm","purl":"pkg:npm/boxy-story-header"},"versions":["35.7.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-story-header/MAL-2026-13085.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"886adc6301f0a8605a8a9ed1e0cf2bf754f1fbc6266a051fa9b227e3ca61ab28","tlsh":"31a1966a05a630188b70d7e1c717541af66af5637680c294f79ca9981ff2224c3f2efc","path":"setup.js"},{"sha256":"e0aae0138a282ad0323edb1d141cacd2c191b138a6884d3f51c24b8fbd9b69b5","tlsh":"a3835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}],"package_integrity":[{"filename":"boxy-story-header-35.7.2.tgz","hashes":{"sha1":"eea29bbd58013d3613bda7442c731293614bc668","sha512_sri":"sha512-IHLeYKOCDtVdOPEpMwn66QOd5mQH46pYUOxCM8tClqXMxgP4TT1xkTB0fDcT4j2eQBdlkySvK6E8y3XviiDTBQ=="}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}