Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malware in dolyame-boxy-independent-bnpl-mobile-application

Malware was discovered in the npm package dolyame-boxy-independent-bnpl-mobile-application. Systems with this package installed are considered fully compromised and require immediate remediation.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system with the package installed or running
Ecosystems
Attack vectors
Affected entities
  • dolyame-boxy-independent-bnpl-mobile-application

A malware incident was identified in the npm package dolyame-boxy-independent-bnpl-mobile-application. According to the GitHub advisory, any computer with this package installed or running should be considered fully compromised.

The advisory recommends immediate rotation of all secrets and keys stored on affected systems from a different, uncompromised computer. While the malicious package should be removed, there is no guarantee that removal will eliminate all malicious software that may have been installed as a result of the package installation, given the potential for full system compromise.

Affected systems should be treated as potentially under external control and require comprehensive security review and remediation beyond simple package removal.

Indicators of compromise

Packages
  • dolyame-boxy-independent-bnpl-mobile-application

Remediation

  • Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer
  • Remove the dolyame-boxy-independent-bnpl-mobile-application package from all affected systems
  • Conduct a comprehensive security audit of all systems that had this package installed
  • Monitor affected systems for signs of persistent malware or unauthorized access
  • Consider full system reimaging if the package was installed on critical infrastructure

Sources

  1. GitHub Advisory GHSA-9368-qf6c-gcr6 · GitHub Advisory Database

Cite this entry

"Malware in dolyame-boxy-independent-bnpl-mobile-application." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 5, 2026; last updated August 5, 2026. https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-mobile-application-g7an35

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in akamai-sensor (npm)

    A malicious npm package named akamai-sensor impersonated Akamai's legitimate sensor_data anti-bot SDK. The package contained hidden JavaScript code concealed using invisible Unicode characters and implemented a dynamic command-and-control channel via a Google Calendar dead-drop, enabling arbitrary code execution on installation.

    npmCompromised packageTyposquatting
  2. containedcritical

    Malicious code in gunzip-js (npm)

    The npm package gunzip-js version 99.9.1 was identified as malicious by the OpenSSF Package Analysis project. The malicious version communicates with a domain associated with malicious activity.

    npmCompromised package
  3. containedcritical

    Malicious code in akamaijs-sensor (npm)

    The npm package akamaijs-sensor contained malicious code that executed arbitrary JavaScript via hidden Unicode-encoded bytes and established a command-and-control channel through a Google Calendar dead-drop. The package was designed to run attacker-authored code in the consumer's Node process when the sensor() API was called.

    npmCompromised packageMalicious commit
  4. resolvedcritical

    Malicious code in fastly-vcl-language-client (npm)

    The npm package fastly-vcl-language-client contained malicious code in a preinstall script that collected system information and CI environment variables, exfiltrating data to an external webhook endpoint. The package appears to be a dependency-confusion attack targeting internal Fastly tooling.

    npmCompromised packageDependency confusion