MAL-2026-13074

    Dashboard / Malicious Package / MAL-2026-13074

    MAL-2026-13074

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in boxy-page-story (npm)

    Details: Source: amazon-inspector (6cb3184221c24b500fca09d9e96c886b1ffe703d60b121150180b2387a87c48d) On require, index.js loads./_runtime, which reconstructs C2 hostnames from string-array concatenation to hide four oob-worker.cf1{00,01,02,03}-*.workers.dev endpoints and a wel1.ru DNS-TXT covert-channel fallback (chunk-count TXT at c.<domain>, base64 chunks at <n>.<domain>, reassembled and base64-decoded). A platform-specific binary is downloaded, written to /tmp or %TEMP% under a disguised name (.cache_<hex> on Unix, dotnet_diag_<hex>.exe on Windows), chmod 0755'd, and spawned detached via /bin/sh -c "<path> &" or cmd.exe /c start /b. No hash or signature verification; hosts are attacker-controlled non-publisher infrastructure. Fetch is gated by absence of a recent cache file and DO_NOT_TRACK-style env vars. index.js wraps the require in try/catch to swallow errors silently.

    Affected packages

    Package

    Name: boxy-page-story

    Purl: pkg:npm/boxy-page-story

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.8.5
    MAL-2026-13074 | CVE-DB