{"id":"MAL-2026-13137","summary":"Malicious code in dolyame-ui-block (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7d0fed433faae413825a41330dcf81ec06db856008fdf7ebb4cd3e385626b4ce)\nOn require of the package's main entry (index.js), _adapter.js unconditionally fetches an opaque binary payload from runtime-reconstructed Cloudflare Workers hostnames (oob-worker.cf1{00-03}-*.workers.dev) with a DNS-TXT-based fallback loader under *.dl.wel1.ru. The payload is written to a hidden path in /tmp or %TEMP% under a disguised name (.cache_\u003chex\u003e on POSIX, dotnet_diag_\u003chex\u003e.exe on Windows), marked executable with chmod 0755, and launched via a detached spawn of /bin/sh -c or cmd. No hash or signature verification is performed. Endpoint hostnames are assembled via array split/join to evade static string matching, and a DNS-TXT channel reads a base64-encoded payload split across numbered TXT records at 0..N.\u003cresolver-domain\u003e. Re-execution is gated by a timestamp file at /tmp/.analytics_state. The behavior has no relationship to a UI-components package and matches an install/import-time remote code execution dropper with deliberate obfuscation and evasion.\n","modified":"2026-08-05T15:52:40.486869751Z","published":"2026-08-05T15:18:31Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.1.8"],"id":"IN-MAL-2026-015647","import_time":"2026-08-05T15:20:01.537686316Z","modified_time":"2026-08-05T15:18:31Z","sha256":"7d0fed433faae413825a41330dcf81ec06db856008fdf7ebb4cd3e385626b4ce"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-block/v/35.1.8"}],"affected":[{"package":{"name":"dolyame-ui-block","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-block"},"versions":["35.1.8"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-block/MAL-2026-13137.json","indicators":{"package_integrity":[{"hashes":{"sha1":"adf8197b1a025d7f2a9c8e82de5a7d3787d1a02b","sha512_sri":"sha512-i8nJUWM56tMZ6fLaixRpGTx4Rex8gkamStvrO5+i/HpugsfVR3D2ytqvKZv6DsibNKJYlmZDURtdJvCoz224kg=="},"filename":"dolyame-ui-block-35.1.8.tgz"}],"evidence_files":[{"tlsh":"39a1879a166670188fb097e4c61b8826f65bf65337c0c2c4fb9c65985f735248272efc","path":"_adapter.js","sha256":"b1c1c3a4d7533151fd72fe6f1414407f983d6baba68b0a121e9cec617ae1d74e"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}