MAL-2026-13077
Dashboard / Malicious Package / MAL-2026-13077
MAL-2026-13077
Summary: Malicious code in boxy-render-unwrap (npm)
Details: Source: amazon-inspector (26755161d9a2ac85d670783fc7eb67383b08592dbb67899b916d3e521d560420) On require of boxy-render-unwrap, index.js loads _bootstrap.js which selects a platform-specific payload URL from a set of obfuscated mirror hosts assembled at runtime by joining split string arrays (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS TXT chunked-base64 fallback over subdomains under dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru). _bootstrap.js fetches the opaque binary via https.get, writes it to /tmp or %TEMP% under disguised names (dotnet_diag_<rnd>.exe on Windows,.cache_<rnd> on POSIX), chmods 0o755 on POSIX, and spawns it detached via cp.spawn("/bin/sh", ["-c", fp + " &"], {detached:true}).unref() or cmd /c start /b on Windows. A stamp file named.analytics_state is written to mimic legitimate telemetry. Merely importing the package causes fetch-and-execute of attacker-controlled native code on the installer's machine.
Affected packages
Package
Name: boxy-render-unwrap
Purl: pkg:npm/boxy-render-unwrap
Affected ranges
Type: N/A
Events:
