MAL-2026-13128

    Dashboard / Malicious Package / MAL-2026-13128

    MAL-2026-13128

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in dolyame-boxy-mobile-bnpl-text-block (npm)

    Details: Source: amazon-inspector (9e5ba9319e9ab791d3944f19baaae57aac3c2d381bf03ccf736d8ae09a2ba4b6) On any require() of the package, index.js loads./_compat.js, which fetches a native binary from string-fragmented Cloudflare Workers hosts under oob-worker.cf*.workers.dev (with a DNS TXT-record fallback that reassembles base64 chunks from subdomains under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru), writes the payload to /var/tmp or %TEMP% under a disguised name (dotnet_diag_<hex>.exe on Windows,.cache_<hex> on Unix), chmods it 0755, and spawns it detached via /bin/sh -c or cmd /c start. Network destinations are hidden by array-joining fragmented substrings and require() is invoked as require('child_'+'process') to evade static matching. No integrity check, no consent prompt, and only an environment-variable opt-out. A dormant secondary dropper in lib/telemetry.js ships in the tarball with the same spawn/chmod/base64 shape framed as an analytics SDK, but is not reached from index.js in this version.

    Affected packages

    Package

    Name: dolyame-boxy-mobile-bnpl-text-block

    Purl: pkg:npm/dolyame-boxy-mobile-bnpl-text-block

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.1.8
    MAL-2026-13128 | CVE-DB