MAL-2026-13071
Dashboard / Malicious Package / MAL-2026-13071
MAL-2026-13071
Summary: Malicious code in boxy-mmb-deps-pvm-plugin (npm)
Details: Source: amazon-inspector (088639f9b19ce8234cef116c0250628c6894bd509915aa90639c56436ec19646) index.js unconditionally loads _polyfill.js on require. _polyfill.js reconstructs attacker-controlled hostnames from split string literals (oob-worker.cf101-adf.workers.dev, cf102-baf.workers.dev, cf99-9b3.workers.dev, cf100-416.workers.dev), downloads a platform-specific binary via https.get, and — if HTTPS fails — falls back to a DNS TXT covert channel that reassembles base64-chunked payload bytes from c.<domain> and <i>.<domain> lookups against sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The fetched bytes are written to /var/tmp/.cache_<hex> or %TEMP%\dotnet_diag_<hex>.exe, chmod 0755, and spawned detached via /bin/sh -c or cmd /c start. lib/telemetry.js ships a second copy of the same dropper under an 'analytics-sdk' cover story, loading child_process through require("child_"+"process") and calling fs["chmod"+"Sync"] to further hide the pattern. The package's stated 'plugin' purpose does not match the shipped payload-delivery infrastructure.
Affected packages
Package
Name: boxy-mmb-deps-pvm-plugin
Purl: pkg:npm/boxy-mmb-deps-pvm-plugin
Affected ranges
Type: N/A
Events:
