VDB
EN

MAL-2026-13148

Malicious code in dolyame-ui-confirmation (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (dba60f94522cc371a13cce00e6a8e51678812f3f50f3e577fd5e9275295a72e0) dolyame-ui-confirmation@35.3.3 ships a _shim.js that is require()d from index.js at module load. On import, _shim.js detects the host OS/architecture, downloads a native binary from one of three Cloudflare Workers hosts whose names are assembled by joining split substrings at runtime (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS TXT fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru whose labels are similarly reconstructed. The downloaded bytes are written to /tmp or %TEMP% under a decoy name (dotnet_diag_<hex>.exe on Windows,.cache_<hex> on POSIX), chmod 0755 on POSIX, and executed detached via cmd.exe /c start or /bin/sh -c fp+' &'. A /tmp/.analytics_state marker throttles reruns. lib/telemetry.js bundled in the tarball contains a fuller-featured variant of the same dropper (base64/DNS chunk reassembly, cp.spawn('/bin/sh', ['-c', filePath+' &']), fs['chmod'+'Sync'] with 0755). The obfuscation of destinations, decoy filenames, cover comments referencing 'CDN compatibility' and 'analytics_state', and the mismatch with the package's stated React-UI purpose are all consistent with a supply-chain dropper. Installing or importing this package fetches and executes an attacker-controlled native binary on the installer's machine.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / dolyame-ui-confirmation

No fixed version published yet for dolyame-ui-confirmation (npm). Pin to a known-safe version or switch to an alternative.

참고