MAL-2026-13127

    Dashboard / Malicious Package / MAL-2026-13127

    MAL-2026-13127

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in dolyame-boxy-mobile-bnpl-popup (npm)

    Details: Source: amazon-inspector (1830a31476314b9c1be462eba26a2314ed333d547a3f55bb62ff7ca44b5c9074) On require(), index.js loads _loader.js which selects a platform-specific payload path, fetches bytes over HTTPS from obfuscated hosts assembled via string-split concatenation (oob-worker.cf1-02-baf.workers.dev and siblings) with a DNS-TXT fallback that reassembles a base64 payload from numbered TXT records under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes the payload to /tmp/.cache_<rand> or %TEMP%/dotnet_diag_<rand>.exe, chmods 0755, and detached-spawns it via spawn('/bin/sh',['-c', fp+' &']) or spawn('cmd',...). No signature or hash verification is performed, hosts are obfuscated to evade static analysis, staging paths and filenames mimic telemetry/diagnostic naming, and the package name misappropriates a payments-BNPL brand context that has no legitimate reason to fetch and execute arbitrary binaries at import time.

    Affected packages

    Package

    Name: dolyame-boxy-mobile-bnpl-popup

    Purl: pkg:npm/dolyame-boxy-mobile-bnpl-popup

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.1.9
    MAL-2026-13127 | CVE-DB