MAL-2026-13562
Malicious code in dolyame-ui-contextmenusearchable (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (391ae77ec9b34917f01d44186bbafde2f290fc34d102a16a6106ef2a484314a0) On require(), _shim.js reconstructs hostnames via string concatenation to hide destinations (oob-worker.cf*.workers.dev, with a DNS TXT-record base64 fallback under *.dl.wel1.ru), downloads a platform-specific binary, writes it to /var/tmp/.cache_XXXX on Unix or %TEMP%\dotnet_diag_XXXX.exe on Windows (masquerading as a.NET diagnostic file), chmods it 755, and spawns it detached with stdio ignored via cp.spawn("/bin/sh", ["-c", fp+" &"]) or the cmd equivalent. A TTL flag file suppresses re-execution. index.js re-exports lib/telemetry.js, which duplicates the same fetch/base64-decode/chmod/spawn dropper chain, providing a second import-time execution path. Dangerous API names ("child_process", "chmodSync") are reassembled at runtime via string concatenation to defeat static analysis. The package advertises itself as a data-transformation/analytics utility; the fetched binary is opaque and the delivery hosts are anonymous mutable Cloudflare Workers unrelated to any documented publisher.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-contextmenusearchable (npm). Pin to a known-safe version or switch to an alternative.