{"id":"MAL-2026-13337","summary":"Malicious code in dolyame-boxy-mobile-bnpl-button-set (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ce4829363e0b5248ca374f2bd545b219d5235bbc96936ba5bd9d06f369878538)\nOn require, index.js loads _shim.js which selects a platform-specific endpoint from a set of runtime-assembled Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS-TXT base64 fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. Hostnames are hidden by splitting across array fragments joined at runtime. _shim.js downloads an opaque binary payload with no hash or signature verification, writes it to /tmp or %TEMP% under decoy filenames (dotnet_diag_\u003crand\u003e.exe on Windows,.cache_\u003crand\u003e on Unix), chmods it 0755, and spawns it detached via cmd.exe /c start or /bin/sh -c '\u003cfile\u003e &'. A marker file analytics_state/.analytics_state is written, stderr logging is suppressed, and environment opt-outs (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) frame the dropper as telemetry. A dormant 81 KB lib/telemetry.js contains a parallel download-write-chmod-spawn code path with base64 payload reassembly, not currently referenced. The declared purpose of the package (a BNPL button UI component) does not require fetching or executing native binaries.\n","modified":"2026-08-05T16:50:59.105686225Z","published":"2026-08-05T15:19:43Z","database_specific":{"malicious-packages-origins":[{"sha256":"ce4829363e0b5248ca374f2bd545b219d5235bbc96936ba5bd9d06f369878538","source":"amazon-inspector","versions":["35.8.1"],"id":"IN-MAL-2026-015655","import_time":"2026-08-05T16:13:28.825443393Z","modified_time":"2026-08-05T15:19:43Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-boxy-mobile-bnpl-button-set/v/35.8.1"}],"affected":[{"package":{"name":"dolyame-boxy-mobile-bnpl-button-set","ecosystem":"npm","purl":"pkg:npm/dolyame-boxy-mobile-bnpl-button-set"},"versions":["35.8.1"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"c52a8e005c80e158b98dc3f0b0ee95ea9910b071651198ae6afbbfb310e38103","tlsh":"6ab1b69a165a60184bb0ebe0cb175815f56ef6633781c294f75c65881fb312483b2efc","path":"_shim.js"},{"path":"lib/telemetry.js","sha256":"0d4b899dff222daef963fed3ee1b0c8ae8672e61f12e786c211df735eaaf5f61","tlsh":"4e835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"dolyame-boxy-mobile-bnpl-button-set-35.8.1.tgz","hashes":{"sha512_sri":"sha512-kePXddWfxWsR2d6AYqKkI3suJaPT9736tgzRVLGWdF3x99NX/f9VV+EYCN4r9mcey+St8aO9vt2PTzJQN3SWzQ==","sha1":"2a514f9c10180bc2717be8e919290320bde8cf49"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-boxy-mobile-bnpl-button-set/MAL-2026-13337.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}