Logo
npm

dolyame-boxy-atom-bnpl-store-button@20.5.3

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC

Malicious

OSV ID

MAL-2026-12364

Ecosystem

npm

Summary

On require, index.js loads _loader.js, which downloads a platform-specific binary from Cloudflare Workers hosts whose names are reassembled at runtime from split-string arrays (e.g. oob-worker.cf1XX-*.workers.dev), with a DNS-TXT chunked fallback resolving under *.dl.well1.site. The binary is written to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmodded 0755, and detached-spawned via /bin/sh -c or cmd /c start /b (_loader.js line 121-127). Hostname strings are split across array literals joined at runtime, and comments frame the behavior as 'telemetry' with DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK opt-outs as cover. A separate lib/telemetry.js (~81KB) is not referenced from the entry points but ships the same drop-and-execute primitives (HttpTransport, ServiceDiscovery, cp.spawn('/bin/sh',[ '-c', filePath+' &']), chmodSync 0755, base64 chunk buffering) as a redundant loader. The package name mimics a Russian BNPL merchant integration but its only observable effect on require is fetching and executing an unverified remote binary.

Source: amazon-inspector (b82cb3b1e0ca7de56472ae3d263144d8131faf53d64761943decb8937fd5bc6a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.