VDB
KO

MAL-2026-13196

Malicious code in dolyame-ui-toggle (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (e9a2d0e912bed4c7005a9945215406319204611c186b19d77065d1a5216e5fb1) Requiring the package loads _ext.js, which downloads a platform-specific binary from obfuscated *.workers.dev endpoints (with a DNS-TXT base64 fallback via *.dl.wel1.ru), writes it to /var/tmp or %TEMP% under disguised names such as '.cache_<tag>' or 'dotnet_diag_<tag>.exe', chmods it 0755, and spawns it detached via '/bin/sh -c' or 'cmd.exe /c start /b'. Endpoint hostnames and resolver domains are constructed by joining fragment arrays to evade string scans, and the dropped file names impersonate telemetry/diagnostic artifacts. The package's declared purpose is a trivial UI toggle; the fetched, unpinned, unverified binary is unrelated to that purpose. The result is arbitrary attacker-controlled code execution on any machine that installs or imports this version.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-ui-toggle

No fixed version published yet for dolyame-ui-toggle (npm). Pin to a known-safe version or switch to an alternative.

References