{"id":"MAL-2026-13094","summary":"Malicious code in boxy-use-calls (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (41e7b8d0b1d87131f56439454c512c68c367ed421c04c7a4bc165c7aeb6acdd6)\nindex.js unconditionally requires _bridge.js, whose top-level main() runs on import. _bridge.js selects a platform-specific payload path, downloads an opaque binary via https.get from one of several string-split Cloudflare-Workers hosts assembled by.join('') (oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev), writes it to a disguised filename under /tmp or %TEMP% (e.g..cache_\u003chex\u003e, dotnet_diag_\u003chex\u003e.exe), chmods it 0755, and detached-spawns it via /bin/sh -c or cmd /c start with.unref(). A fallback channel queries DNS TXT records under c.\u003cdomain\u003e and sequentially-numbered subdomains of *.dl.wel1.ru to reassemble a base64-chunked payload when HTTPS is blocked. A 21376-second replay-suppression stamp is written under an 'analytics_state' key. No pinning, no signature check, no publisher-matching source. A separate lib/telemetry.js file presents an 81 KB 'analytics SDK' that is never referenced by index.js or _bridge.js and shares DISABLE_TELEMETRY/ANALYTICS_OPT_OUT env-var names with _bridge.js, serving as cover-story camouflage for the dropper.\n","modified":"2026-08-05T15:52:19.850031721Z","published":"2026-08-05T14:23:06Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.1.8"],"id":"IN-MAL-2026-015280","import_time":"2026-08-05T15:19:42.291496437Z","modified_time":"2026-08-05T14:23:06Z","sha256":"41e7b8d0b1d87131f56439454c512c68c367ed421c04c7a4bc165c7aeb6acdd6"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/boxy-use-calls/v/35.1.8"}],"affected":[{"package":{"name":"boxy-use-calls","ecosystem":"npm","purl":"pkg:npm/boxy-use-calls"},"versions":["35.1.8"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"_bridge.js","sha256":"e02d018431751618c654deeab717ec45234c7e3bc2f1abc296536124a46fb311","tlsh":"52a1765a16aa71188bb0e7e0c7174415f65af6633391c284fb9c65d45fb312483b2efc"},{"sha256":"49904d944277fc74ae1a1df5e10943dbab4e2712c84d8d489c4805557f843cd5","tlsh":"eb835055566a142186b2b378df234107ff3685272642429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}],"package_integrity":[{"hashes":{"sha1":"f6542c813c519a1556ca36e3eee47e24ec2e0d20","sha512_sri":"sha512-Ar67WfKFyz2EDla3WkVbV1rboIr7BhdG9/x8Nj4cDmgZATHMb56+Wx/WZV50RelYtdpCq5UtIDxdhyQZCxGFMg=="},"filename":"boxy-use-calls-35.1.8.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-use-calls/MAL-2026-13094.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}