MAL-2026-13138
Malicious code in dolyame-ui-breadcrumbs (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (7679dd0e86411f0df5eea8392ad6f6a663ab0d911cd674b3ef4605af846cb323) On require() of dolyame-ui-breadcrumbs, index.js loads _bridge.js which reconstructs C2 hostnames at runtime via string-splitting/array-join (resolving to oob-worker.cf<id>.workers.dev with a DNS-TXT chunked fallback via sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), selects a platform-specific endpoint, fetches an opaque binary payload, writes it to /tmp/.cache_<uid> on Unix or %TEMP%/dotnet_diag_<uid>.exe on Windows under disguised names, chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. A freshness marker is written to /tmp/.analytics_state. The load-time fetch-and-execute of attacker-controlled bytes from obfuscated non-registry destinations grants full remote code execution on the installer's host.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-breadcrumbs (npm). Pin to a known-safe version or switch to an alternative.