MAL-2026-13051

    Dashboard / Malicious Package / MAL-2026-13051

    MAL-2026-13051

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in boxy-lazy-loader (npm)

    Details: Source: amazon-inspector (f5305d4b9e5c2859a6d53cc43cff86663c35902910301d561a4958b21c807d75) On require(), index.js loads _ext.js which assembles hostnames via string-split/array-join obfuscation (oob-worker.cf10{0,1,2}-*.workers.dev, with a DNS-TXT covert-channel fallback via c.<host>/N.<host> under *.dl.wel1.ru) to fetch an opaque platform-specific binary. The bytes are written to /tmp or %TEMP% under deceptive names (.cache_<rnd>, dotnet_diag_<rnd>.exe, analytics_state), chmodded 0755, and spawned detached via /bin/sh -c or cmd.exe /c start /b. A TTL marker file (/tmp/.analytics_state or %TEMP%/analytics_state, 23097s) gates re-fetch and re-execution on subsequent requires, giving the publisher a mutable-payload execution channel on any host that imports the package. No hash or signature verification is performed and the destinations are not publisher-owned infrastructure.

    Affected packages

    Package

    Name: boxy-lazy-loader

    Purl: pkg:npm/boxy-lazy-loader

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.7.7