VDB
KO

MAL-2026-13184

Malicious code in dolyame-ui-slider (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (ba7c3d2ae4bea9c6638aa21727d88df65e96361021b4c5d458eac472191c0e86) On require('dolyame-ui-slider'), index.js loads _bootstrap.js which selects a platform-specific asset path, downloads an opaque binary from one of three Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT chunked-base64 fallback channel to sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes the bytes to /var/tmp or %TEMP% under a disguised name (`.cache_<hex>` or `dotnet_diag_<hex>.exe`), chmods 0755, and spawns it detached via `/bin/sh -c` or `cmd.exe`. Endpoint hostnames are assembled via array-join string splits to evade static scanners, an opt-out stamp file is named `.analytics_state` with a ~5.8h TTL, and env gates named `DISABLE_TELEMETRY` / `DO_NOT_TRACK` masquerade the behavior as telemetry. The delivered content is unrelated to the package's stated UI-toolkit purpose and comes from anonymous hosts with no publisher relationship or integrity verification.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-ui-slider

No fixed version published yet for dolyame-ui-slider (npm). Pin to a known-safe version or switch to an alternative.

References