MAL-2026-13167
Malicious code in dolyame-ui-menu (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (cecad37efa23b83ead95d73e1b0ef07dbb8473dfd76645f4ceed5cf7939653f4) The package is published as a React UI component library but on require('dolyame-ui-menu'), index.js loads _polyfill.js which fetches a platform-specific native binary from attacker-controlled Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS-TXT chunked-base64 fallback channel over c./0./1./... subdomains of sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. All destination hostnames are assembled at runtime via array.join to defeat static string matching. The fetched bytes are written to a disguised path in /tmp or %TEMP% using cover-story names such as.cache_<uid>, dotnet_diag_<uid>.exe, and a.analytics_state marker file, chmod'd 0755, and executed detached via spawn('/bin/sh', ['-c', fp + ' &']) or cmd.exe /c start /b, with no hash or signature verification. Execution is gated by DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK env vars and a filesystem TTL marker to avoid re-running in analysis environments. The advertised UI-library purpose is unrelated to any of this behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-menu (npm). Pin to a known-safe version or switch to an alternative.