MAL-2026-13145
Malicious code in dolyame-ui-clickable (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (f92051e4b21bd0bc9562833662ba7e1e9185bc8342bcc8bbbac8fc4d848c4dbe) On require() of the package, index.js unconditionally loads _init.js, which selects a platform-specific endpoint (linux_x64, linux_arm64, darwin, win32) and downloads a native binary from a rotating list of anonymous Cloudflare Workers subdomains (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS TXT fallback via sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The fetched bytes are written to /var/tmp/.cache_<hex> or %TEMP%/dotnet_diag_<hex>.exe, chmod'd 0755, and spawned detached via cp.spawn("/bin/sh", ["-c", fp + " &"], {detached:true}) or the Windows equivalent. Hostnames and sensitive API names (child_process, chmodSync) are reassembled at runtime from split string arrays to evade static matching, and the code is framed with cover-story comments as analytics/telemetry. A second, ~81 KB copy of the same fetch-and-execute pattern ships in lib/telemetry.js, using the same string-split evasion and a base64-decoded payload piped to /bin/sh with chmod 0755. The declared purpose (a UI-components package) has no need for native binary execution from anonymous infrastructure.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-clickable (npm). Pin to a known-safe version or switch to an alternative.