{"id":"MAL-2026-13158","summary":"Malicious code in dolyame-ui-group (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (714598919807b4143a734772e690ff94aa986fb6cf61bd99026e7f7bc93f4cf2)\nOn require() of the package's main entry, _loader.js runs a platform-detecting downloader that fetches an executable from obfuscated hostnames reconstructed at runtime via array-join splits (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS-TXT covert-channel fallback to sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru. The downloaded bytes are written to a temp path with cover-story names (dotnet_diag_\u003crand\u003e.exe on Windows,.cache_\u003crand\u003e on POSIX), chmod 0755, and spawned detached via /bin/sh -c or cmd. A second co-shipped dropper module lib/telemetry.js, styled as an analytics SDK, contains the same base64-decode -\u003e write -\u003e chmod 755 -\u003e spawn(\"/bin/sh\", [\"-c\", filePath+\" &\"]) chain. Sensitive API names are hidden via string concatenation (require(\"child_\"+\"process\"), fs[\"chmod\"+\"Sync\"], os[\"host\"+\"name\"]()) to defeat static grep. Fetch-and-execute of an opaque, unversioned, non-publisher binary from anonymous workers.dev infrastructure at library-load time is arbitrary code execution on the installer's host.\n","modified":"2026-08-05T15:52:50.853303786Z","published":"2026-08-05T15:13:53Z","database_specific":{"malicious-packages-origins":[{"sha256":"714598919807b4143a734772e690ff94aa986fb6cf61bd99026e7f7bc93f4cf2","source":"amazon-inspector","versions":["35.9.7"],"id":"IN-MAL-2026-015617","import_time":"2026-08-05T15:20:00.393545722Z","modified_time":"2026-08-05T15:13:53Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-group/v/35.9.7"}],"affected":[{"package":{"name":"dolyame-ui-group","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-group"},"versions":["35.9.7"],"database_specific":{"indicators":{"package_integrity":[{"filename":"dolyame-ui-group-35.9.7.tgz","hashes":{"sha1":"20754c9cd124bd68d94888a92822a178bc6200da","sha512_sri":"sha512-rz+3EcIa8O7RyZmYGu/s9wOpwSxXrAYM498t3oNd9uIrNononZkz5usmDuB050Jmj9abPqjp5LEfUKnVK2mnZA=="}}],"evidence_files":[{"sha256":"04ce4f8e201d3f8a5cde4091830a9481381e74eeaf758ccc00188dde9c37d26f","tlsh":"c3b1755a127a70184bb0abe4871b5416f65bf6633780c2d8f79ca5985f7312482b2efc","path":"_loader.js"},{"tlsh":"dd835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js","sha256":"646b7a587a343cb027b81f02e864a9dfbdbfa152fa41a37a57e5c53e0bdf1e49"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-group/MAL-2026-13158.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}