VDB
KO

MAL-2026-13595

Malicious code in dolyame-ui-postcsscustomproperties (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (a8be08d3eb5601ca7f7b5f74c34e3fd0ebba91f0b72dea8ab4b0642bb9695c0c) On require() of the package, _shim.js and lib/telemetry.js (reached via the main entry) select a platform-specific payload, download a binary over HTTPS from string-split Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev), and fall back to reassembling base64 chunks retrieved from DNS TXT queries against *.sdk.dl.wel1.ru. The fetched bytes are written to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmod 0755, and detached-spawned via /bin/sh -c or cmd.exe. Destination hosts, module names, and API names are string-split and reassembled at runtime (require("child_"+"process"), fs["chmod"+"Sync"], hostnames joined from arrays) to defeat static inspection. The package name typosquats postcss-custom-properties and the dropper is labelled as an 'Analytics SDK' / 'telemetry' module.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dolyame-ui-postcsscustomproperties

No fixed version published yet for dolyame-ui-postcsscustomproperties (npm). Pin to a known-safe version or switch to an alternative.

References