VDB
KO

MAL-2026-13157

Malicious code in dolyame-ui-grid (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (f21d1f60c7f97ffdc8e698c9804d9d9116f286be7a026a9c90f6e4a1858dea18) On require('dolyame-ui-grid'), index.js loads _polyfill.js which selects a platform-specific asset, downloads a binary from one of four hardcoded Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev) with DNS-TXT chunked fallbacks under *.dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), writes it to /tmp or the Windows Temp directory under a disguised name (.cache_<rand> or dotnet_diag_<rand>.exe), chmods it 0755, and spawns it detached via spawn('/bin/sh') or spawn('cmd'). Destination hostnames are assembled at runtime by.join('') on split string fragments, and a.analytics_state mtime file gates re-execution cadence, with comments framing the code as 'telemetry'/'analytics'. A parallel dropper implementation in lib/telemetry.js (base64-decoded chunks, chmodSync 0755, cp.spawn('/bin/sh',['-c', filePath+' &'])) is present but not reachable from the main require graph. The download hosts are unrelated to the package publisher, the fetched bytes are opaque and unverified, and execution happens unconditionally on module load.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-ui-grid

No fixed version published yet for dolyame-ui-grid (npm). Pin to a known-safe version or switch to an alternative.

References