VDB
KO

MAL-2026-13199

Malicious code in dolyame-ui-utils (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (899f518db368635c0c794a8097fc0af3a2c85f61cdb4dcfbd81b0cf85629f199) On require of the package, _polyfill.js selects a platform-keyed URL, fetches an opaque binary over HTTPS from string-split-obfuscated Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with a base64-chunked DNS-TXT fallback channel over *.dl.wel1.ru, writes it to /tmp/.cache_<hex> or %TEMP%\dotnet_diag_<hex>.exe, chmods 0755, and spawns it detached via /bin/sh -c or cmd /c start. No hash or signature verification is performed and destinations are unrelated to the package publisher. lib/telemetry.js ships a parallel dropper implementation with additional evasion (split require("child_"+"process"), dynamic fs["chmod"+"Sync"]) as staged secondary payload. An analytics_state marker file and DISABLE_TELEMETRY env var provide cover framing.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-ui-utils

No fixed version published yet for dolyame-ui-utils (npm). Pin to a known-safe version or switch to an alternative.

References