{"id":"MAL-2026-13331","summary":"Malicious code in dolyame-boxy-independent-bnpl-table (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fd3ad7593e26ae49876e0310a51ac122ddcb6878eefddc74a5828cce061d200b)\nOn require() of the package, index.js loads _init.js which assembles obfuscated Cloudflare Workers hostnames (oob-worker.cf*.workers.dev) from string-split fragments joined at runtime, with a DNS-TXT-based fallback resolver using *.dl.wel1.ru domains. It downloads a platform-specific binary (/pkg/package, /pkg/package.exe, /pkg/loader_mac, /pkg/package-arm64) via https.get, writes the opaque payload to /var/tmp or the Windows TEMP directory under disguised names (.cache_\u003chex\u003e or dotnet_diag_\u003chex\u003e.exe), chmods it to 0755, and spawns it detached via /bin/sh -c or cmd /c start. A stamp file at /tmp/.analytics_state rate-limits re-execution, and DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK env vars are honored as a cover story framing this as an analytics SDK. A second module, lib/telemetry.js, is bundled in the same tarball with the same fetch-decode-write-chmod-spawn shape and additional API-name concatenation obfuscation (require('child_'+'process'), fs['chmod'+'Sync']). Package name and 'bnpl-table' framing do not match the observed behavior.\n","modified":"2026-08-05T16:50:56.479496953Z","published":"2026-08-05T15:20:30Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015660","import_time":"2026-08-05T16:13:29.29098405Z","modified_time":"2026-08-05T15:20:30Z","sha256":"fd3ad7593e26ae49876e0310a51ac122ddcb6878eefddc74a5828cce061d200b","source":"amazon-inspector","versions":["35.3.4"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-boxy-independent-bnpl-table/v/35.3.4"}],"affected":[{"package":{"name":"dolyame-boxy-independent-bnpl-table","ecosystem":"npm","purl":"pkg:npm/dolyame-boxy-independent-bnpl-table"},"versions":["35.3.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-boxy-independent-bnpl-table/MAL-2026-13331.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"1331649a992253aab6fabe5e108956d9158bb6e3eb40a343258276e9e2fa6dee","tlsh":"29a1655a1669b0184b70dbe4c61b8826f667f6533780d2c4fb9c65985f7312482b2efc","path":"_init.js"},{"path":"lib/telemetry.js","sha256":"534239748629354d8cac60f5342345a65584c53bbe51d5c16c30d421096da5a3","tlsh":"34835055566a202186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"hashes":{"sha1":"beae4939a7a63d4437dbd841044dccf7ab3acf16","sha512_sri":"sha512-nsnl0bPuyuD2o26kLYThHsDKIwY5N1k+UKdNAvQOkHINJZghDn4rPailqhA62Lgzt5olG+I9qtE4SFYDUqDtgQ=="},"filename":"dolyame-boxy-independent-bnpl-table-35.3.4.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}