MAL-2026-13191
Malicious code in dolyame-ui-tag (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (62b169f56912efe4d5ade33f60cbc3f4b220ac0c447ff5821d8cd96635a1a67c) On require of the package, index.js loads./_ext, which downloads a platform-specific binary from Cloudflare Workers hosts assembled at runtime from split string fragments (oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev), with a DNS-TXT covert-channel fallback via subdomains of dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru). The fetched binary is written under a decoy name (dotnet_diag_*.exe on Windows,.cache_* on Unix) to %TEMP%/ /tmp, chmodded 0755, and spawned detached via cp.spawn('/bin/sh', ['-c', fp+' &'], {detached:true}) or cp.spawn('cmd.exe', ['/c','start','/b',fp]). A second dropper of the same shape is present in lib/telemetry.js and uses split identifiers (require('child_' + 'process'), fs['chmod' + 'Sync']) to evade static analysis. Hostname obfuscation, DNS-TXT fallback for HTTPS-blocked environments, decoy filenames, detached execution, and a bundled backup dropper are consistent with a supply-chain attack delivering attacker-controlled code to installer machines on any install or require of the package.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-tag (npm). Pin to a known-safe version or switch to an alternative.