MAL-2026-13180
Malicious code in dolyame-ui-react-wrapper (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (67a3c87278303f582f0f5f046a5edcaf081cd71ed9c00906d36d3bbba5911a33) On require, index.js loads _helpers.js which runs setup() at module load. The setup routine reconstructs mirror hostnames at runtime by joining split string fragments (e.g. 'oob-worker.cf101-adf.workers.dev', 'oob-worker.cf100-416.workers.dev', 'oob-worker.cf103-070.workers.dev') and DNS-discovery domains ('sdk.dl.wel1.ru', 'ext.dl.wel1.ru', 'pkg.dl.wel1.ru', 'net.dl.wel1.ru') with a DNS TXT base64 fallback, downloads a platform-specific binary via https.get, writes it to /tmp or the Windows Temp directory under disguised names such as '.cache_<hex>' and 'dotnet_diag_<hex>.exe', chmods it 0755, and spawns it detached through '/bin/sh -c' or 'cmd'. The package name presents as a UI React wrapper for an unrelated payments brand, unrelated to the actual behavior, and string obfuscation of hostnames serves only to defeat scanners.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-react-wrapper (npm). Pin to a known-safe version or switch to an alternative.