npm

dolyame-boxy-block @35.5.2

Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 4:49 AM UTC

Malicious

OSV ID

MAL-2026-13298

Ecosystem

npm

Summary

dolyame-boxy-block@35.5.2 ships a _runtime.js module that is unconditionally required from index.js at load time. On import, _runtime.js reconstructs attacker-controlled hostnames from split string arrays (e.g. ["oob-wor","ker.cf99-9b3.workers.dev"].join("") producing oob-worker.cf99-9b3.workers.dev , and similar for oob-worker.cf100-416.workers.dev , oob-worker.cf101-adf.workers.dev , oob-worker.cf103-070.workers.dev ), performs an https.get to a platform-specific endpoint, writes the returned bytes to /var/tmp or %TEMP% under a decoy filename ( .cache_<rand> on POSIX, dotnet_diag_<rand>.exe on Windows), chmod 0755 s the file, and spawns it detached via /bin/sh -c "<path> &" or cmd.exe with stdio:"ignore" and .unref() . If the HTTPS mirrors fail, a DNS-TXT covert channel under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru retrieves a base64-encoded payload chunked across multiple TXT records ( c.<domain> , 0.<domain> , 1.<domain> ...), reassembles it, and executes it through the same write-and-spawn sink. The advertised purpose ("boxy block" UI library) does not match the shipped behavior; the hostnames are obfuscated to evade static string search; the fetched binary is unpinned, unhashed, and unsigned. Any consumer that require() s or import s the package triggers full-host remote code execution.

Source: amazon-inspector (919c54c4e8e0b08b62f76b85369a9033929f8ea19dfc777b8ece48697229a5ce)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.