VDB
KO

MAL-2026-13577

Malicious code in dolyame-ui-inputdate (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (338935a6ea459d3f1882101939a348b871a9cf59d49003f5e04eb65afd60c484) On require()/import, index.js loads./_ext.js which selects a platform-specific remote endpoint, downloads an opaque binary via HTTPS from string-split-obfuscated Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with a base64-over-DNS-TXT fallback channel across sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The downloaded bytes are written to a hidden temp file (.cache_<rand> / dotnet_diag_<rand>.exe), chmod 0755, and spawned detached via /bin/sh -c or cmd. Hostname reconstruction from split-string arrays and the DNS covert-channel fallback demonstrate deliberate evasion. The package's stated purpose ('API client wrappers') does not correspond to any of this behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-ui-inputdate

No fixed version published yet for dolyame-ui-inputdate (npm). Pin to a known-safe version or switch to an alternative.

References