MAL-2026-13182

    Dashboard / Malicious Package / MAL-2026-13182

    MAL-2026-13182

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in dolyame-ui-select (npm)

    Details: Source: amazon-inspector (1d1d8b1348e86f0f476ab27b5d5cde1c6a4cfd519e74e526a82263c78a0aaf6b) On require of the package, index.js loads _bridge.js, which reconstructs C2 hostnames from split string fragments (resolving to oob-worker.cf103-07.workers.dev, oob-worker.cf99-9b3.workers.dev, and oob-worker.cf100-416.workers.dev), downloads a platform-specific binary from /pkg/package[.exe|-arm64|_mac], writes it to /var/tmp/.cache_<hex> or %TEMP%\dotnet_diag_<hex>.exe, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. A DNS TXT covert channel over *.dl.wel1.ru (c.<domain> count + <n>.<domain> base64 chunks) provides a fallback transport when HTTPS egress is blocked. Cover-story identifiers such as `analytics` and `dotnet_diag` disguise the payload, and a ~20455s persistence flag paces re-execution. A second, larger dropper variant with the same behavior ships as lib/telemetry.js (~81KB) under an `analytics-sdk` cover story, ready to be wired in.

    Affected packages

    Package

    Name: dolyame-ui-select

    Purl: pkg:npm/dolyame-ui-select

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.9.5
    MAL-2026-13182 | CVE-DB