MAL-2026-13298

    Dashboard / Malicious Package / MAL-2026-13298

    MAL-2026-13298

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in dolyame-boxy-block (npm)

    Details: Source: amazon-inspector (919c54c4e8e0b08b62f76b85369a9033929f8ea19dfc777b8ece48697229a5ce) [email protected] ships a `_runtime.js` module that is unconditionally required from `index.js` at load time. On import, `_runtime.js` reconstructs attacker-controlled hostnames from split string arrays (e.g. `["oob-wor","ker.cf99-9b3.workers.dev"].join("")` producing `oob-worker.cf99-9b3.workers.dev`, and similar for `oob-worker.cf100-416.workers.dev`, `oob-worker.cf101-adf.workers.dev`, `oob-worker.cf103-070.workers.dev`), performs an `https.get` to a platform-specific endpoint, writes the returned bytes to `/var/tmp` or `%TEMP%` under a decoy filename (`.cache_<rand>` on POSIX, `dotnet_diag_<rand>.exe` on Windows), `chmod 0755`s the file, and spawns it detached via `/bin/sh -c "<path> &"` or `cmd.exe` with `stdio:"ignore"` and `.unref()`. If the HTTPS mirrors fail, a DNS-TXT covert channel under `sdk.dl.wel1.ru` / `ext.dl.wel1.ru` / `pkg.dl.wel1.ru` / `net.dl.wel1.ru` retrieves a base64-encoded payload chunked across multiple TXT records (`c.<domain>`, `0.<domain>`, `1.<domain>`...), reassembles it, and executes it through the same write-and-spawn sink. The advertised purpose ("boxy block" UI library) does not match the shipped behavior; the hostnames are obfuscated to evade static string search; the fetched binary is unpinned, unhashed, and unsigned. Any consumer that `require()`s or `import`s the package triggers full-host remote code execution.

    Affected packages

    Package

    Name: dolyame-boxy-block

    Purl: pkg:npm/dolyame-boxy-block

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.5.2
    MAL-2026-13298 | CVE-DB