MAL-2026-13563
Malicious code in dolyame-ui-controlgroup (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (099af2a758510302726d266aeefb46cb91473a6a42c9484e068f465ea1509e84) On require() of dolyame-ui-controlgroup, _compat.js selects a per-OS/arch URL and downloads a native binary from string-split-obfuscated hostnames (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev) with a DNS-over-TXT fallback under sdk.dl.wel1.ru, writes it to a temp file with a hidden/randomized name (dotnet-diag-lookalike), chmods 0755, and spawns it detached via `/bin/sh -c` or `cmd.exe /c start /b`. The declared main lib/telemetry.js duplicates the dropper via a base64-decoded buffer written to disk, chmod 755, and `/bin/sh -c` spawn, so the payload fires from the main module even if the _compat require is removed. Hostnames and dangerous API identifiers (`child_process`, `chmodSync`) are assembled at runtime via `.join("")` and dynamic property access to evade string search. The download hosts, endpoints, and destination filenames are unrelated to the package's advertised monitoring/observability purpose.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-controlgroup (npm). Pin to a known-safe version or switch to an alternative.