{"id":"MAL-2026-13148","summary":"Malicious code in dolyame-ui-confirmation (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dba60f94522cc371a13cce00e6a8e51678812f3f50f3e577fd5e9275295a72e0)\ndolyame-ui-confirmation@35.3.3 ships a _shim.js that is require()d from index.js at module load. On import, _shim.js detects the host OS/architecture, downloads a native binary from one of three Cloudflare Workers hosts whose names are assembled by joining split substrings at runtime (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS TXT fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru whose labels are similarly reconstructed. The downloaded bytes are written to /tmp or %TEMP% under a decoy name (dotnet_diag_\u003chex\u003e.exe on Windows,.cache_\u003chex\u003e on POSIX), chmod 0755 on POSIX, and executed detached via cmd.exe /c start or /bin/sh -c fp+' &'. A /tmp/.analytics_state marker throttles reruns. lib/telemetry.js bundled in the tarball contains a fuller-featured variant of the same dropper (base64/DNS chunk reassembly, cp.spawn('/bin/sh', ['-c', filePath+' &']), fs['chmod'+'Sync'] with 0755). The obfuscation of destinations, decoy filenames, cover comments referencing 'CDN compatibility' and 'analytics_state', and the mismatch with the package's stated React-UI purpose are all consistent with a supply-chain dropper. Installing or importing this package fetches and executes an attacker-controlled native binary on the installer's machine.\n","modified":"2026-08-05T15:52:45.988373031Z","published":"2026-08-05T15:15:18Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015626","import_time":"2026-08-05T15:20:00.756265099Z","modified_time":"2026-08-05T15:15:18Z","sha256":"dba60f94522cc371a13cce00e6a8e51678812f3f50f3e577fd5e9275295a72e0","source":"amazon-inspector","versions":["35.3.3"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-confirmation/v/35.3.3"}],"affected":[{"package":{"name":"dolyame-ui-confirmation","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-confirmation"},"versions":["35.3.3"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-confirmation/MAL-2026-13148.json","indicators":{"evidence_files":[{"tlsh":"67b1a7a6056a301987b0d7e5c31b6816f657f65373808294f79c99980ff6218c3b3eec","path":"_shim.js","sha256":"ab6cd67cc122d558ca1b21c1dad699fa7419c08ad5de7eaae816aa0d0c6b3900"},{"sha256":"8a7e34036e30026e3de8f071bc94cf9424ed1cb1227b9d8ac2125903551ad8ba","tlsh":"0b835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}],"package_integrity":[{"hashes":{"sha1":"efe3448426852b845ff86e85dd70264ad3fb2883","sha512_sri":"sha512-0zaH2ha0YiySO9lxOQ26U0Ns+jfJ6Wv7CpIc4aBpX/NcBiedClGghDawUBfazREWf7/TE0Un/Nf8K50+6zzCbg=="},"filename":"dolyame-ui-confirmation-35.3.3.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}