MAL-2026-13143
Malicious code in dolyame-ui-checkable (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (6ab13fa73d76681896cf6b34c1b61c2c417f03226865384355020bc5a4a0381c) index.js unconditionally requires./setup.js on load, so any require/import of the package auto-executes a dropper. setup.js reconstructs a list of Cloudflare workers.dev mirror hosts (e.g. oob-worker.cf103-070.workers.dev) via array.join string-splitting, downloads a platform-specific binary over HTTPS, writes it to /tmp or %TEMP% under a disguised name (dotnet_diag_<rand>.exe,.cache_<rand>), chmods it 0755 on POSIX, and spawns it detached via cmd.exe or /bin/sh -c. When HTTPS mirrors fail, setup.js queries DNS TXT records on numeric subdomains of sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, concatenates the chunks, base64-decodes them into a binary, writes it to disk, and executes it — a DNS-tunneled executable delivery channel designed to bypass HTTPS egress filtering. lib/telemetry.js contains a second copy of the same dropper primitives (require("child_"+"process"), fs["chmod"+"Sync"], cp.spawn("/bin/sh", ["-c", filePath+" &"], {detached: true})) wrapped in Sentry-lookalike SDK framing. String-splitting of hostnames and API names, mismatch between the advertised "UI checkable" purpose and the fetch-and-exec behavior, use of anonymous workers.dev endpoints, and the DNS-TXT covert channel together characterize a hostile install/import-time dropper.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for dolyame-ui-checkable (npm). Pin to a known-safe version or switch to an alternative.