MAL-2026-13162
Malicious code in dolyame-ui-label (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (bdcede6d4d42bfed7f10577346b24e9af22655e50f8d454baab6f4999e6020f3) dolyame-ui-label 35.7.8 is not a UI component library. On require() of the package, index.js loads _helpers.js, which reconstructs C2 hostnames at runtime from split-string arrays (e.g. ["oob","-worker.cf102-baf.workers.dev"].join("") and ['sdk.dl.wel','1.','ru'].join("")) to evade static inspection. It selects a platform-specific endpoint among oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, and oob-worker.cf103-070.workers.dev, with a DNS-TXT base64 fallback via sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, downloads a native binary via https.get, writes it to /tmp/.cache_<rand> on Unix or %TEMP%\dotnet_diag_<rand>.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd. Cover-story comments frame the traffic as analytics/telemetry/CDN. The package's declared purpose (UI labels) has no legitimate need for a native binary drop, and the destinations are unrelated to any documented publisher, unpinned, and unverified.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-label (npm). Pin to a known-safe version or switch to an alternative.