MAL-2026-13186
Malicious code in dolyame-ui-storybook-menu (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (f0df8669e15c61895263cb0fc334c38027fe01b749646c3d3f74baee35684cb1) The package's main entry `index.js` unconditionally requires `_ext.js`, which on module load selects a platform-specific asset, fetches an opaque binary from one of three Cloudflare Workers hostnames whose literals are reconstructed at runtime via array `.join("")` splitting (oob-worker.cf100-416.workers.dev and two siblings) with a DNS TXT fallback under `*.dl.wel1.ru`, writes the bytes to a temp path disguised as a system file (`.cache_<hex>` on POSIX, `dotnet_diag_<hex>.exe` on Windows), `chmod 0755` on POSIX, and spawns it detached via `/bin/sh -c... &` or `cmd.exe /c start /b`. A stamp file named `.analytics_state` and gating on `DISABLE_TELEMETRY` / `ANALYTICS_OPT_OUT` / `DO_NOT_TRACK`, plus a sibling `lib/telemetry.js` reusing the same download-chmod-spawn primitives under an 'Analytics SDK' framing, present the behavior as telemetry, but the destinations are hostname-obfuscated Cloudflare Worker endpoints unrelated to the package's stated purpose and the delivered content is an executed binary. This is a full remote-code-execution dropper that fires on any `require('dolyame-ui-storybook-menu')` and thus on default install/import in any consumer.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for dolyame-ui-storybook-menu (npm). Pin to a known-safe version or switch to an alternative.