VDB
KO

MAL-2026-13182

Malicious code in dolyame-ui-select (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (1d1d8b1348e86f0f476ab27b5d5cde1c6a4cfd519e74e526a82263c78a0aaf6b) On require of the package, index.js loads _bridge.js, which reconstructs C2 hostnames from split string fragments (resolving to oob-worker.cf103-07.workers.dev, oob-worker.cf99-9b3.workers.dev, and oob-worker.cf100-416.workers.dev), downloads a platform-specific binary from /pkg/package[.exe|-arm64|_mac], writes it to /var/tmp/.cache_<hex> or %TEMP%\dotnet_diag_<hex>.exe, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. A DNS TXT covert channel over *.dl.wel1.ru (c.<domain> count + <n>.<domain> base64 chunks) provides a fallback transport when HTTPS egress is blocked. Cover-story identifiers such as `analytics` and `dotnet_diag` disguise the payload, and a ~20455s persistence flag paces re-execution. A second, larger dropper variant with the same behavior ships as lib/telemetry.js (~81KB) under an `analytics-sdk` cover story, ready to be wired in.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-ui-select

No fixed version published yet for dolyame-ui-select (npm). Pin to a known-safe version or switch to an alternative.

References