Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in dolyame-boxy-independent-bnpl-main-title (npm)

The npm package dolyame-boxy-independent-bnpl-main-title contained malicious code that downloads and executes platform-specific binaries on require. The package disguised itself as a BNPL (Buy Now Pay Later) module while performing fetch-and-exec operations via obfuscated Cloudflare Workers and DNS fallback mechanisms.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any Node.js application that installed the malicious package version
Ecosystems
Attack vectors
Affected entities
  • dolyame-boxy-independent-bnpl-main-titlenpm package containing malicious code in index.js and _polyfill.js

The npm package dolyame-boxy-independent-bnpl-main-title was found to contain malicious code designed to execute arbitrary binaries on the host system. Upon require, the package's index.js loads _polyfill.js, which reconstructs hostnames from fragmented strings to contact multiple Cloudflare Workers subdomains.

The malicious payload downloads a platform-specific binary and writes it to system temporary directories: /tmp/.cache_ on Unix systems or %TEMP%\dotnet_diag_.exe on Windows. The binary is then executed with elevated permissions (chmod 0755) via /bin/sh -c on Unix or cmd on Windows, with standard input/output redirected to /dev/null.

To evade detection, the package employed multiple obfuscation techniques: naming the malicious script polyfill.js to appear legitimate, using cache markers labeled "analytics_state," naming the Windows payload "dotnet_diag.exe" to mimic .NET diagnostics, and setting environment variables like DISABLE_TELEMETRY and ANALYTICS_OPT_OUT. A DNS TXT record fallback under *.dl.wel1.ru was configured to reassemble base64-encoded payloads via chunked transfer when HTTPS connections were blocked.

The incident was identified and credited to the OpenSSF's malicious-packages repository.

Indicators of compromise

Packages
  • dolyame-boxy-independent-bnpl-main-title
Domains
  • *.cf99-9b3.workers.dev
  • *.dl.wel1.ru

Remediation

  • Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials.

Sources

  1. GitHub Advisory GHSA-8pq3-r6vr-xr6x · GitHub Advisory Database

Cite this entry

"Malicious code in dolyame-boxy-independent-bnpl-main-title (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 7, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-independent-bnpl-main-title-npm-xf7pbx

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    Malware in eslint-generate-prerelease

    Malware was discovered in the npm package eslint-generate-prerelease. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  2. activecritical

    Malware in celonix-otp-react

    Malware discovered in the npm package celonix-otp-react. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  3. containedcritical

    Malware in resolve-audit

    The npm package resolve-audit was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised and all secrets/keys rotated immediately from a different machine.

    npmCompromised package
  4. resolvedcritical

    Malware in alphazone

    The npm package alphazone contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package