MAL-2026-13150
Dashboard / Malicious Package / MAL-2026-13150
MAL-2026-13150
Summary: Malicious code in dolyame-ui-container (npm)
Details: Source: amazon-inspector (0b0f03a063fb3a6b8c7605612b587eddfefa6181b85b14654ee93f267dd790e1) On require of the package, index.js loads _compat.js, which at module load time downloads a platform-specific binary from hostnames assembled at runtime via string-splitting (oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev). If HTTPS mirrors fail, it falls back to a DNS-over-TXT covert channel, resolving TXT records under *.dl.wel1.ru subdomains and base64-decoding the concatenated response into a binary. The fetched payload is written to a disguised path under /tmp or %TEMP% (e.g. dotnet_diag_<hex>.exe,.cache_<hex>), chmod 0755, and spawned detached via cmd.exe or /bin/sh -c with no hash or signature verification. Environment variable checks (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) and analytics-styled filenames provide cover. The destinations are not the publisher's infrastructure and the retrieval mechanism is inconsistent with any legitimate distribution channel.
Affected packages
Package
Name: dolyame-ui-container
Purl: pkg:npm/dolyame-ui-container
Affected ranges
Type: N/A
Events:
