MAL-2026-13332

    Dashboard / Malicious Package / MAL-2026-13332

    MAL-2026-13332

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in dolyame-boxy-independent-bnpl-text-block (npm)

    Details: Source: amazon-inspector (0d558b476b362ab912d18912a13c79e326b5fcdcdbe73b0f292d94aa89ac732d) On require() of the package, index.js loads _runtime.js, which assembles Cloudflare Workers hostnames (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev) and DNS-TXT fallback hosts under dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru) from split-and-joined string fragments to conceal them from static analysis. It fetches a platform-specific executable payload from those hosts, writes it to a randomly-named file in /tmp or %TEMP% with cover-story names (dotnet_diag_<rnd>.exe,.cache_<rnd>,.analytics_state), chmods it 0755 on Unix, and spawns it detached via /bin/sh -c or cmd /c start. The tarball also ships lib/telemetry.js, an ~81KB unreferenced sibling module implementing the same fetch-write-chmod-spawn pattern with base64-reconstructed payload bytes and string-concatenated 'child_'+'process' / 'chmod'+'Sync' references. The package's declared purpose as a BNPL text-block UI helper has no relationship to the observed dropper behavior.

    Affected packages

    Package

    Name: dolyame-boxy-independent-bnpl-text-block

    Purl: pkg:npm/dolyame-boxy-independent-bnpl-text-block

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.5.3
    MAL-2026-13332 | CVE-DB