{"id":"MAL-2026-13155","summary":"Malicious code in dolyame-ui-flag (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (be48c86f2b67912c3cfa1849431e5eb3d45510c55bb1fa98ab304dc36d25097b)\nOn require() of the package, index.js loads _vendor.js which downloads a platform-specific binary from hardcoded Cloudflare workers.dev hosts (oob-worker.cf10{1,2,3}-*.workers.dev) with a DNS-TXT chunked base64 fallback resolved via sdk.dl.wel1.ru, writes it to /tmp or the Windows Temp directory under a disguised name (.cache_\u003chex\u003e or dotnet_diag_\u003chex\u003e.exe), chmods 755, and spawns it detached via /bin/sh -c \"\u003cpath\u003e &\" or cmd.exe /c start /b. Destination hostnames and dangerous APIs are assembled by array-join and string concatenation (e.g. require(\"child_\"+\"process\"), fs[\"chmod\"+\"Sync\"]) to hinder pattern-matching. A second, structurally identical dropper is shipped in lib/telemetry.js under an 'Analytics SDK' label, providing a backup payload vector. The advertised purpose (a UI flag component) has no relationship to fetching and executing opaque native binaries from anonymous Workers hosts.\n","modified":"2026-08-05T15:52:49.353725372Z","published":"2026-08-05T15:14:34Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015621","import_time":"2026-08-05T15:20:00.511209859Z","modified_time":"2026-08-05T15:14:34Z","sha256":"be48c86f2b67912c3cfa1849431e5eb3d45510c55bb1fa98ab304dc36d25097b","source":"amazon-inspector","versions":["35.7.6"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-flag/v/35.7.6"}],"affected":[{"package":{"name":"dolyame-ui-flag","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-flag"},"versions":["35.7.6"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"_vendor.js","sha256":"dd017d0359480ff311cd0a41b6710e59e914cd8eb493a2906cda3fcf4f5ad95b","tlsh":"7da1a99a12a5b0188fb0d7e0c71b9815f65bf663368182d4f79c65944f731248372dfc"},{"path":"lib/telemetry.js","sha256":"c5be733436d7d5b4876806970b3686136a813084243ab1e8a4ab22fb7074ad09","tlsh":"1e835056566a142186b2b368df234107ff3685272642429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"dolyame-ui-flag-35.7.6.tgz","hashes":{"sha512_sri":"sha512-YLymA1VppXy8nP+AhfmJUch8NBMVBEEDpeheaC/rleqsgCwAaj2PAkJetWTEZ9jIq3xp1rWF+pfP1kJ80Dc+ew==","sha1":"c975cde6205536d52f3820642b9b5d6758f1782b"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-flag/MAL-2026-13155.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}