{"id":"MAL-2026-13086","summary":"Malicious code in boxy-storybook-addon-changelog (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0ec351f143fde732be84b60d329ba254cda918df3ebb25882371a8c5d96a3dd0)\nOn require of the package, index.js loads _ext.js which downloads an opaque platform-specific binary from one of four hardcoded Cloudflare Workers hosts (oob-worker.cf*.workers.dev), with a DNS-TXT chunked base64 fallback via *.dl.wel1.ru resolvers. Hostnames are reassembled at runtime via Array.join to evade static inspection. The fetched payload is written to /var/tmp/.cache_\u003chex\u003e on Unix or %TEMP%\\dotnet_diag_\u003chex\u003e.exe on Windows, chmod 0755'd, and spawned detached via /bin/sh -c \"\u003cpath\u003e &\" or cmd.exe /c start /b, then unref()'d. A second module lib/telemetry.js bundles the same dropper primitives (child_process spawn, fs.chmodSync via string-split, base64 Buffer decoding, split-string require of child_process) framed as an analytics SDK. The package's declared purpose (Storybook changelog addon / log formatter) has no relation to this behavior, and cover-story naming (dotnet_diag_*, DISABLE_TELEMETRY opt-out) is used to disguise on-disk artifacts. Package name resembles legitimate Storybook addons.\n","modified":"2026-08-05T15:52:15.897957454Z","published":"2026-08-05T14:24:24Z","database_specific":{"malicious-packages-origins":[{"versions":["35.1.2"],"id":"IN-MAL-2026-015287","import_time":"2026-08-05T15:19:42.707867047Z","modified_time":"2026-08-05T14:24:24Z","sha256":"0ec351f143fde732be84b60d329ba254cda918df3ebb25882371a8c5d96a3dd0","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-storybook-addon-changelog/v/35.1.2"}],"affected":[{"package":{"name":"boxy-storybook-addon-changelog","ecosystem":"npm","purl":"pkg:npm/boxy-storybook-addon-changelog"},"versions":["35.1.2"],"database_specific":{"indicators":{"evidence_files":[{"path":"_ext.js","sha256":"c792553c21ab6b869a7fc31b98179c32ee5181f1800ef31a3ebe5c6cb1bef1a0","tlsh":"2da1545a16a571084bb09be48717441af65bf6633780c694fbac75981fb322483b2efc"},{"sha256":"87aa4b5e7bc9e629404e3e33207e503392b60d964800c0120eb69f910d679be0","tlsh":"29835055566a242186b2b368df234107ff3685272643429dbaec82dc1fbd72092a5ffc","path":"lib/telemetry.js"}],"package_integrity":[{"filename":"boxy-storybook-addon-changelog-35.1.2.tgz","hashes":{"sha512_sri":"sha512-MCnOg8Dr6VRF7ZojtQwXi5N7Akk/mlm6ca0gOYGJiIMRlxwxSD4K0WRkQlvu8i8UEpjLGc/gPRekbk4zDoXVaQ==","sha1":"7a1c6a588871f3770e836aaadda68d1beb1455a2"}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-storybook-addon-changelog/MAL-2026-13086.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}