LWA-2026-7429 MAL-2026-12384 ↗ confirmed malware

form-bnpl-dolyame-component-object@20.8.9

Malicious code in form-bnpl-dolyame-component-object (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1027 · Obfuscated Files or InformationT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1572 · Protocol Tunneling

Analysis

form-bnpl-dolyame-component-object@20.8.9 is a trojanized npm package that downloads and executes a second-stage binary on the installer's machine. On require(), the package's _polyfill.js collects the host OS and architecture, then attempts to download a binary payload from attacker-controlled Cloudflare Workers infrastructure at oob-worker[.]cf99-9b3[.]workers[.]dev, oob-worker[.]cf102-baf[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev, and oob-worker[.]cf101-adf[.]workers[.]dev (path: /pkg/package). If HTTPS fails, it falls back to DNS TXT chunked transfer via c[.]tin[.]dl[.]well1[.]site. The downloaded binary is written to /var/tmp/.cache_<random> (or %TEMP%\dotnet_diag_<random>.exe on Windows), made executable, and spawned as a detached background process. A filesystem stamp at /tmp/.analytics_state prevents re-download within ~6 hours. The package has no repository, no README, and no documented purpose — it is a pure dropper.

analyzed by
Leitwacht
first seen
Aug 2, 2026, 10:56 AM
analyzed
Aug 2, 2026, 10:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.