MAL-2026-13150
Malicious code in dolyame-ui-container (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (0b0f03a063fb3a6b8c7605612b587eddfefa6181b85b14654ee93f267dd790e1) On require of the package, index.js loads _compat.js, which at module load time downloads a platform-specific binary from hostnames assembled at runtime via string-splitting (oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev). If HTTPS mirrors fail, it falls back to a DNS-over-TXT covert channel, resolving TXT records under *.dl.wel1.ru subdomains and base64-decoding the concatenated response into a binary. The fetched payload is written to a disguised path under /tmp or %TEMP% (e.g. dotnet_diag_<hex>.exe,.cache_<hex>), chmod 0755, and spawned detached via cmd.exe or /bin/sh -c with no hash or signature verification. Environment variable checks (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) and analytics-styled filenames provide cover. The destinations are not the publisher's infrastructure and the retrieval mechanism is inconsistent with any legitimate distribution channel.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-container (npm). Pin to a known-safe version or switch to an alternative.