MAL-2026-13092

    Dashboard / Malicious Package / MAL-2026-13092

    MAL-2026-13092

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in boxy-tokens (npm)

    Details: Source: amazon-inspector (bfb29953971bb0c3eae94e97f7a9efe132bd4a954252ae52c989f990f389d098) index.js unconditionally requires./setup.js on module load. setup.js assembles Cloudflare Workers hostnames from split-string arrays (oob-worker.cf1-01-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), selects a platform-specific asset (linux_x64, linux_arm64, darwin, win32), downloads an opaque binary via https.get, writes it to /var/tmp/.cache_<rnd> or %TEMP%\dotnet_diag_<rnd>.exe, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start with no hash or signature verification. A DNS-TXT fallback channel reconstructs *.dl.wel1.ru from a split array, reads a chunk count from c.<domain>, fetches N base64-encoded TXT records from numbered subdomains, and concatenates them into an executable buffer that is executed the same way. Filenames impersonate dotnet diagnostic artifacts and cache files. Any consumer that requires boxy-tokens runs the attacker's binary on their host.

    Affected packages

    Package

    Name: boxy-tokens

    Purl: pkg:npm/boxy-tokens

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.5.2