MAL-2026-13533

    Dashboard / Malicious Package / MAL-2026-13533

    MAL-2026-13533

    Published: 7 Aug 2026Last Modified: 7 Aug 2026

    Summary: Malicious code in ded-pwa-c-boxy (npm)

    Details: Source: amazon-inspector (b2293ad47611dcfbb22a3ef81df5e4f27dc942bd2bd2fc5865b60948dc6fc671) On require() of the package, index.js loads _vendor.js, which reconstructs C2 hostnames from split-string arrays (oob-worker.cf102-baf.workers.dev and sdk.dl.wel1.ru, with a DNS-TXT covert-channel fallback), fetches a platform-specific opaque binary over HTTPS, writes it to /var/tmp or %TEMP% under names disguised as system caches (.cache_<hex> / dotnet_diag_<hex>.exe), chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. The loader is invoked from index.js inside a try/catch that swallows all errors, gated on env variables DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK and a filesystem TTL marker to evade repeated analysis. The package.json declares the package as 'Reusable ded pwa c boxy components' with no dependencies and index.js exposes only a trivial DedPwaCBoxy class — the declared purpose is unrelated to any native-binary component. Destinations are anonymous Cloudflare Workers subdomains and a lookalike DNS namespace, not a publisher-owned or documented distribution host.

    Affected packages

    Package

    Name: ded-pwa-c-boxy

    Purl: pkg:npm/ded-pwa-c-boxy

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.9.1
    MAL-2026-13533 | CVE-DB