MAL-2026-13187
Dashboard / Malicious Package / MAL-2026-13187
MAL-2026-13187
Summary: Malicious code in dolyame-ui-styles (npm)
Details: Source: amazon-inspector (c154e71b3fe4bf6957b180aa41ecdc789c11ea90928aab8c66c52a90c6428051) On require of the package's main entry, index.js loads _platform.js which assembles obfuscated hostnames via array.join("") to reach oob-worker.cf*.workers.dev, downloads a platform-specific binary, writes it to /var/tmp/.cache_<hex> on POSIX or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. A covert DNS-TXT fallback channel (loadViaDns) reads a chunk count from c.<domain> and base64-reassembles the executable payload from numbered TXT records under *.dl.wel1.ru. Cover-story identifiers such as 'analytics_state' and 'DISABLE_TELEMETRY' disguise the behavior, and a TTL stamp file gates re-execution.
Affected packages
Package
Name: dolyame-ui-styles
Purl: pkg:npm/dolyame-ui-styles
Affected ranges
Type: N/A
Events:
