MAL-2026-13196
Malicious code in dolyame-ui-toggle (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (e9a2d0e912bed4c7005a9945215406319204611c186b19d77065d1a5216e5fb1) Requiring the package loads _ext.js, which downloads a platform-specific binary from obfuscated *.workers.dev endpoints (with a DNS-TXT base64 fallback via *.dl.wel1.ru), writes it to /var/tmp or %TEMP% under disguised names such as '.cache_<tag>' or 'dotnet_diag_<tag>.exe', chmods it 0755, and spawns it detached via '/bin/sh -c' or 'cmd.exe /c start /b'. Endpoint hostnames and resolver domains are constructed by joining fragment arrays to evade string scans, and the dropped file names impersonate telemetry/diagnostic artifacts. The package's declared purpose is a trivial UI toggle; the fetched, unpinned, unverified binary is unrelated to that purpose. The result is arbitrary attacker-controlled code execution on any machine that installs or imports this version.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-toggle (npm). Pin to a known-safe version or switch to an alternative.