MAL-2026-13582
Malicious code in dolyame-ui-inputsearch (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (0146bdcb21ca52b35e8a6f3ca19b7203b1fb5a456eb9dff6ace2eb60348333fe) dolyame-ui-inputsearch@35.8.1 is a dropper disguised as a UI input search component. On require, index.js loads./_vendor.js, which assembles a mirror list of Cloudflare workers.dev endpoints (oob-worker.cf103-070.workers.dev, cf101-adf.workers.dev, cf102-baf.workers.dev) from string-concatenation-split literals, with a DNS-TXT fallback resolving base64-encoded download data via sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. A platform-specific binary is downloaded, written to a hidden path (/var/tmp/.cache_<hex> on Unix, TEMP/dotnet_diag_<hex>.exe on Windows), chmod 0755 on Unix, then spawned detached via /bin/sh -c or cmd. Endpoints and filenames are split-literal obfuscated and gated behind cover-story flags named analytics_state and DISABLE_TELEMETRY, and the dropped filename impersonates.NET diagnostics tooling. The purpose of the fetched binary is opaque; the delivery mechanism has no hash or signature verification, no pinning, and no publisher-matched host. The purpose (dropper of an anonymous remote binary) is unrelated to the advertised UI input search functionality.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dolyame-ui-inputsearch (npm). Pin to a known-safe version or switch to an alternative.