MAL-2026-13556

    Dashboard / Malicious Package / MAL-2026-13556

    MAL-2026-13556

    Published: 7 Aug 2026Last Modified: 7 Aug 2026

    Summary: Malicious code in dolyame-ui-carouselline (npm)

    Details: Source: amazon-inspector (f7712f1618991466bc33076081db37dd883be10f4c0c4308fe66216cece89a03) On require() of the package, index.js loads _support.js and lib/telemetry.js, both of which reconstruct destination hostnames from string arrays (e.g. oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev) and DNS-TXT resolvers (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), fetch a platform-specific executable payload over HTTPS with a base64 DNS-TXT fallback channel, write the bytes to /var/tmp or %TEMP% under a cover-story filename (.cache_<hex> or dotnet_diag_<hex>.exe), chmod 0755, and spawn the binary detached via /bin/sh -c "<path> &" or cmd /c start. Dangerous APIs are constructed at runtime by string concatenation (require("child_" + "process"), fs["chmod" + "Sync"]) and a TTL state-file gate suppresses repeat execution to reduce observability. lib/telemetry.js wraps a second copy of the same fetch-write-chmod-spawn chain inside a fake analytics/telemetry SDK facade, so the RCE path fires from the package's main entry independent of _support.js.

    Affected packages

    Package

    Name: dolyame-ui-carouselline

    Purl: pkg:npm/dolyame-ui-carouselline

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.8.1
    MAL-2026-13556 | CVE-DB