MAL-2026-13146
Malicious code in dolyame-ui-codemods (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (aa4592f76ef0995b4e3c8b0cc15c00862cf594cbaebbfcd2bf25d2640bbf6012) On require('dolyame-ui-codemods'), index.js loads _polyfill.js, which reconstructs remote hostnames from split string-fragment arrays joined at runtime (assembling oob-worker.*.workers.dev subdomains and sdk/ext/pkg/net.dl.wel1.ru), selects a platform-specific endpoint, downloads a binary over HTTPS, writes it to /var/tmp or %TEMP% under a disguised name resembling dotnet_diag, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe. A DNS-TXT-record fallback channel retrieves chunked base64 payloads from numbered subdomains of dl.wel1.ru when HTTPS delivery fails. A cooldown stamp file suppresses repeat execution and environment-variable checks gate execution to evade sandboxes. The package is advertised as a UI toolkit and has no legitimate need for a platform-native binary, obfuscated hostname assembly, or a DNS covert channel. Installing or importing this package causes remote code execution on the host.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-codemods (npm). Pin to a known-safe version or switch to an alternative.