{"id":"MAL-2026-13144","summary":"Malicious code in dolyame-ui-checkbox (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2a445ffd0f222f7d58ad870ad641f9dd2fb21a1cc43795cbef5c58109cafebbe)\nOn require of the package, index.js loads _vendor.js, which reconstructs a set of C2 hostnames from string-split fragments (four *.workers.dev mirrors and a *.dl.wel1.ru DNS-TXT fallback), selects a per-platform endpoint, downloads an attacker-controlled binary via https.get (or reassembles it from chunked base64 DNS TXT records at c.\u003cdomain\u003e/\u003ci\u003e.\u003cdomain\u003e when HTTPS is blocked), writes it to /var/tmp on Unix or %TEMP% on Windows under cover-story names such as.cache_\u003chex\u003e or dotnet_diag_\u003chex\u003e.exe, chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. A second, functionally equivalent dropper is packaged as lib/telemetry.js (81 KB), disguised as an analytics SDK, implementing the same fetch-\u003echmod 755-\u003espawn('/bin/sh','-c', path+' &') pattern with a base64-decoded payload path. Host reconstruction via string-splitting and the DNS-TXT covert transport are anti-analysis features paired with the dropper.\n","modified":"2026-08-05T15:52:43.999767855Z","published":"2026-08-05T15:16:05Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T15:20:00.987517906Z","modified_time":"2026-08-05T15:16:05Z","sha256":"2a445ffd0f222f7d58ad870ad641f9dd2fb21a1cc43795cbef5c58109cafebbe","source":"amazon-inspector","versions":["35.6.9"],"id":"IN-MAL-2026-015631"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-checkbox/v/35.6.9"}],"affected":[{"package":{"name":"dolyame-ui-checkbox","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-checkbox"},"versions":["35.6.9"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"_vendor.js","sha256":"dec2d9ed93f1d1221ca47a48f208bed542fe1d0bc1f2f545ebb7ad8f238bbd70","tlsh":"0ea1859a12a970184bb097e0c61b4415f95bf6633780d295fb5ca9985fb602483b2efc"},{"path":"lib/telemetry.js","sha256":"e69c6a5ef987e7b69c3f46d197fd568e24039d3d30c400669a9815250db17f77","tlsh":"14835055566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"dolyame-ui-checkbox-35.6.9.tgz","hashes":{"sha1":"d4917cea98efc56fa8dc7a60385ee3da3fbe452d","sha512_sri":"sha512-BXxRHyDyjbEhaJjk+uYDg5+XzmM1YR9R+ix0US5gjypHvbhc7BoRsBkd92FPg3mwflUNIJgXb/CEDzMexuMUzA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-checkbox/MAL-2026-13144.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}