-= Per source details. Do not edit below this line.=-
On require of the package, index.js unconditionally loads compat.js, which reconstructs attacker-controlled hostnames from split string arrays (oob-worker.cf10[0-3]-*.workers.dev and sdk.dl.wel1.ru), selects a per-OS endpoint, and downloads a platform-specific binary from paths such as /pkg/package, /pkg/loader_mac, and /pkg/package.exe. The binary is written to a hidden path (/tmp/.cache on Unix, %TEMP%/dotnet_diag_.exe on Windows under a.NET diagnostics cover name), chmod 0755'd on Unix, and detached-spawned via /bin/sh -c or cmd.exe /c start. A secondary covert channel resolves DNS TXT records for numbered subdomains under sdk.dl.wel1.ru, concatenates the responses, base64-decodes them, and treats the result as an executable payload. A second loader with the same shape is present in lib/telemetry.js under an 'Analytics SDK' cover story, using split identifiers such as require('child_'+'process') and fs['chmod'+'Sync'] to evade static inspection. The package uses hidden filenames, dot-prefixed paths, cover names imitating Microsoft diagnostics, string-array host reassembly, and DNS-TXT payload staging to conceal both the destinations and the behavior.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-015293",
"import_time": "2026-08-05T15:19:43.083270305Z",
"modified_time": "2026-08-05T14:25:15Z",
"sha256": "4ecbc929cc9a3cab12301c7879112bd95abb78812a0248415cc4f7c075d3eec1",
"source": "amazon-inspector",
"versions": [
"35.6.4"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "_compat.js",
"sha256": "965e9718f46d2f927fc71ccb80a935b639aac46fafad09eb02c54e4c38b2baf7",
"tlsh": "e7a1865a116a71198bb0d7e4871b5416f65af6633380c6c8fb5c65980f7316883b2efc"
},
{
"path": "lib/telemetry.js",
"sha256": "9d5e0bea5b16dcad19b6b637619134ea2801b7abe59f9b9bc14598a538f3d079",
"tlsh": "27835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"
}
],
"package_integrity": [
{
"filename": "boxy-service-35.6.4.tgz",
"hashes": {
"sha1": "f3f0696f799ed506c8ddf223783dc14d67993035",
"sha512_sri": "sha512-3tVsyE40dYX4oin9dk4XAydupwqHiGxWv6l3SstZbTgdmnLJnF6P592I4Iwu3StGCzSf8IN6iUoqakycpy04ow=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/boxy-service/MAL-2026-13082.json"