form-bnpl-dolyame-component-object@20.8.9
Malicious code in form-bnpl-dolyame-component-object (npm)
Analysis
form-bnpl-dolyame-component-object@20.8.9 is a trojanized npm package that downloads and executes a second-stage binary on the installer's machine. On require(), the package's _polyfill.js collects the host OS and architecture, then attempts to download a binary payload from attacker-controlled Cloudflare Workers infrastructure at oob-worker[.]cf99-9b3[.]workers[.]dev, oob-worker[.]cf102-baf[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev, and oob-worker[.]cf101-adf[.]workers[.]dev (path: /pkg/package). If HTTPS fails, it falls back to DNS TXT chunked transfer via c[.]tin[.]dl[.]well1[.]site. The downloaded binary is written to /var/tmp/.cache_<random> (or %TEMP%\dotnet_diag_<random>.exe on Windows), made executable, and spawned as a detached background process. A filesystem stamp at /tmp/.analytics_state prevents re-download within ~6 hours. The package has no repository, no README, and no documented purpose — it is a pure dropper.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 10:56 AM
- analyzed
- Aug 2, 2026, 10:56 AM
Related advisories
- tinkoff-pfp-atom-desktop-carousel@20.8.8
- streak-metrics-math@1.0.1
- prisma-callback@1.0.0
- streak-map-kit@1.0.0
- bigops-chats@35.9.6
- bigops-auth-cache@35.3.9
- bigops-cobrowsing@35.4.9
- entropyeasybots@2.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.