{"id":"MAL-2026-13129","summary":"Malicious code in dolyame-boxy-mobile-bnpl-title (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (180d09900ce4462a9d4c9b47dcc26491bfb50aacd5a226a3571211007edb3ad2)\nindex.js unconditionally requires./setup on module load. setup.js branches on process.platform (linux/darwin/win32), fetches an opaque binary from Cloudflare Workers hosts whose names are assembled at runtime from split-string arrays joined together (oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev), with a DNS TXT-record base64 fallback under *.dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru). The fetched bytes are written to /var/tmp/.cache_\u003chex\u003e or %TEMP%\\dotnet_diag_\u003chex\u003e.exe, chmod 0755'd, and spawned detached via cp.spawn('/bin/sh',['-c',fp+' &'],{detached:true}) or cp.spawn('cmd.exe',['/c','start','/b',fp]). No pinning, no hash, no signature verification. Cover-story naming (file 'setup.js', state file '.analytics_state', dropped binary 'dotnet_diag_*.exe', opt-out env vars DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK) frames the behavior as telemetry. lib/telemetry.js (~81 KB) ships the same dropper runtime (Buffer.from(chunks,'base64'); fs['chmod'+'Sync'](path, mode | parseInt('755',8)); cp.spawn('/bin/sh',['-c',filePath+' &']); require('child_'+'process')) though not wired into the current load path. Requiring this package results in arbitrary attacker-controlled code executing on the installer's host with the user's privileges.\n","modified":"2026-08-05T15:52:37.381433452Z","published":"2026-08-05T15:17:59Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T15:17:59Z","sha256":"180d09900ce4462a9d4c9b47dcc26491bfb50aacd5a226a3571211007edb3ad2","source":"amazon-inspector","versions":["35.1.7"],"id":"IN-MAL-2026-015643","import_time":"2026-08-05T15:20:01.357480085Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-boxy-mobile-bnpl-title/v/35.1.7"}],"affected":[{"package":{"name":"dolyame-boxy-mobile-bnpl-title","ecosystem":"npm","purl":"pkg:npm/dolyame-boxy-mobile-bnpl-title"},"versions":["35.1.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"46a1769a16aa701c4bb0a7f4c6174416f656f663338086d8fb9c69981fb352483b1efc","path":"setup.js","sha256":"608070eabc666875356636275ba504977e9570beebef06027324037258545d15"},{"tlsh":"91835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js","sha256":"29555b7d74fe59cf7b5111387d6fa75249c866a80b2583b5d9dc6ca72e9b3369"}],"package_integrity":[{"filename":"dolyame-boxy-mobile-bnpl-title-35.1.7.tgz","hashes":{"sha1":"f1454e7c719f8a29ea27fa7be422b7d46ca43bae","sha512_sri":"sha512-ps7Y9nV2ZLwEsvzO29RF1k7Ic6bYjd80XTRmZNq9qXN+zgC3FTxrWsSGRhV7hUEy8dAv6zUaeCQisJI3zONFfw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-boxy-mobile-bnpl-title/MAL-2026-13129.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}