Malicious code in dolyame-boxy-independent-bnpl-main-title (npm)
The npm package dolyame-boxy-independent-bnpl-main-title contained malicious code that downloads and executes platform-specific binaries on require. The package disguised itself as a BNPL (Buy Now Pay Later) module while performing fetch-and-exec operations via obfuscated Cloudflare Workers and DNS fallback mechanisms.
- Disclosed
- Last updated
- Blast radius
- Any Node.js application that installed the malicious package version
- Ecosystems
- Attack vectors
- Affected entities
- dolyame-boxy-independent-bnpl-main-titlenpm package containing malicious code in index.js and _polyfill.js
The npm package dolyame-boxy-independent-bnpl-main-title was found to contain malicious code designed to execute arbitrary binaries on the host system. Upon require, the package's index.js loads _polyfill.js, which reconstructs hostnames from fragmented strings to contact multiple Cloudflare Workers subdomains.
The malicious payload downloads a platform-specific binary and writes it to system temporary directories: /tmp/.cache_ on Unix systems or %TEMP%\dotnet_diag_.exe on Windows. The binary is then executed with elevated permissions (chmod 0755) via /bin/sh -c on Unix or cmd on Windows, with standard input/output redirected to /dev/null.
To evade detection, the package employed multiple obfuscation techniques: naming the malicious script polyfill.js to appear legitimate, using cache markers labeled "analytics_state," naming the Windows payload "dotnet_diag.exe" to mimic .NET diagnostics, and setting environment variables like DISABLE_TELEMETRY and ANALYTICS_OPT_OUT. A DNS TXT record fallback under *.dl.wel1.ru was configured to reassemble base64-encoded payloads via chunked transfer when HTTPS connections were blocked.
The incident was identified and credited to the OpenSSF's malicious-packages repository.
Indicators of compromise
- Packages
- dolyame-boxy-independent-bnpl-main-title
- Domains
- *.cf99-9b3.workers.dev
- *.dl.wel1.ru
Remediation
- Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials.
Sources
- GitHub Advisory GHSA-8pq3-r6vr-xr6x · GitHub Advisory Database
Cite this entry
"Malicious code in dolyame-boxy-independent-bnpl-main-title (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 7, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-independent-bnpl-main-title-npm-xf7pbx
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in eslint-generate-prerelease
Malware was discovered in the npm package eslint-generate-prerelease. Systems with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in celonix-otp-react
Malware discovered in the npm package celonix-otp-react. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in resolve-audit
The npm package resolve-audit was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised and all secrets/keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malware in alphazone
The npm package alphazone contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.
npmCompromised package