MAL-2026-13184
Malicious code in dolyame-ui-slider (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (ba7c3d2ae4bea9c6638aa21727d88df65e96361021b4c5d458eac472191c0e86) On require('dolyame-ui-slider'), index.js loads _bootstrap.js which selects a platform-specific asset path, downloads an opaque binary from one of three Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT chunked-base64 fallback channel to sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes the bytes to /var/tmp or %TEMP% under a disguised name (`.cache_<hex>` or `dotnet_diag_<hex>.exe`), chmods 0755, and spawns it detached via `/bin/sh -c` or `cmd.exe`. Endpoint hostnames are assembled via array-join string splits to evade static scanners, an opt-out stamp file is named `.analytics_state` with a ~5.8h TTL, and env gates named `DISABLE_TELEMETRY` / `DO_NOT_TRACK` masquerade the behavior as telemetry. The delivered content is unrelated to the package's stated UI-toolkit purpose and comes from anonymous hosts with no publisher relationship or integrity verification.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-slider (npm). Pin to a known-safe version or switch to an alternative.