MAL-2026-13195
Malicious code in dolyame-ui-themes (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (22c23ba8923130746ecc1e526c3a0ee8961ea764dd90d0da71236444d978ce27) dolyame-ui-themes ships a _loader.js that is required from the package main (index.js) at module load. The loader reconstructs C2 hostnames from split string arrays to hide them from static scanners, resolving to oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, and oob-worker.cf103-070.workers.dev, with a covert-channel fallback that retrieves further endpoints from DNS TXT records at sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The loader fetches a platform-specific binary via https.get, writes it to /tmp or %TEMP% under disguised names such as.cache_<hex> or dotnet_diag_<hex>.exe, chmods it 755, and detached-spawns it through /bin/sh -c or cmd.exe. Dangerous APIs are loaded via runtime string concatenation (require("child_" + "process"), fs["chmod"+"Sync"]). A sibling module lib/telemetry.js is framed as an analytics SDK but duplicates the same dropper primitives (base64 chunk decoding, chmod 755, detached /bin/sh spawn) as a parallel loader path. The package name resembles the legitimate dolyame payment integration ecosystem, consistent with a typosquat/lookalike lure. Installing or requiring this package executes an opaque attacker-controlled binary on the installer's host.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-themes (npm). Pin to a known-safe version or switch to an alternative.