{"id":"MAL-2026-13131","summary":"Malicious code in dolyame-boxy-stories (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c0ef68742c490f223f00748b7f5dc82d614231b0d68e430736bbaac9175035e4)\nOn require, index.js loads _bridge.js which selects a platform-specific endpoint and downloads a binary from one of three attacker-controlled hosts whose names are reconstructed at runtime via string.join() to evade static detection (oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS TXT-record fallback under sdk.dl.wel1.ru. The fetched bytes are written to /var/tmp or %TEMP% under disguised filenames (.cache_\u003chex\u003e on Unix, dotnet_diag_\u003chex\u003e.exe on Windows), chmod 0755, and spawned detached via /bin/sh -c or cmd /c start. A marker file.analytics_state and opt-out env vars DISABLE_TELEMETRY / ANALYTICS_OPT_OUT provide cover-story naming; the package's declared purpose is unrelated to any telemetry or analytics function, and the default code path executes the remote binary. This is a load-time full-host RCE dropper.\n","modified":"2026-08-05T15:52:38.689938808Z","published":"2026-08-05T15:18:07Z","database_specific":{"malicious-packages-origins":[{"sha256":"c0ef68742c490f223f00748b7f5dc82d614231b0d68e430736bbaac9175035e4","source":"amazon-inspector","versions":["35.9.7"],"id":"IN-MAL-2026-015644","import_time":"2026-08-05T15:20:01.390051746Z","modified_time":"2026-08-05T15:18:07Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-boxy-stories/v/35.9.7"}],"affected":[{"package":{"name":"dolyame-boxy-stories","ecosystem":"npm","purl":"pkg:npm/dolyame-boxy-stories"},"versions":["35.9.7"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"45a177a615a970184bb0dbe4c7175416f65bf6633380d294fb9ca5d81fb212482b3efc","path":"_bridge.js","sha256":"ae16991dfae9f40a99c8e8f8ffe1585828a2a1c0543b32a3f197948bf05ede58"}],"package_integrity":[{"filename":"dolyame-boxy-stories-35.9.7.tgz","hashes":{"sha1":"a3b33b4724e11414302c5404b57f7c6c06799bdc","sha512_sri":"sha512-CYwjQx4U2ajw26T7k0Z+LaSHBAYfkfnKeFRghWAlHq3czmh8iKzHW9zvO7oXUtY4McPS6JMq/9N370QxhT+nVw=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-boxy-stories/MAL-2026-13131.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}