MAL-2026-13136
Malicious code in dolyame-ui-badge (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (11c1280f596630bc692c2587a15a33bd01b2b745875cfe8a590e6787757867dd) On require() of dolyame-ui-badge, the package loads _bootstrap.js which downloads a native binary from runtime-assembled Cloudflare Workers hosts (oob-worker.cf10{1,2,3}-*.workers.dev) with a DNS TXT-record fallback channel over *.dl.wel1.ru, writes it to /tmp or %TEMP% under disguised names such as dotnet_diag_*.exe and.cache_*, chmods it to 0o755, and spawns it detached via /bin/sh -c or cmd.exe /c start. Destination hostnames are obfuscated by splitting them across array elements and reconstructing at runtime via.join(""). Cover-story comments referencing SHA-256 verification, opt-out flags, and rate-limiting do not correspond to matching code. The package advertises itself as a UI badge component and has no build-time or functional need for a native binary. No signature or hash verification is performed on the downloaded payload.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-badge (npm). Pin to a known-safe version or switch to an alternative.