{"id":"MAL-2026-13159","summary":"Malicious code in dolyame-ui-icon (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (15f91ac3c4278628875a5c009c515bcdb5fbc8b885eb32dff56e4367c5babf66)\nOn require, index.js loads _bootstrap.js which downloads a platform-specific binary from hardcoded Cloudflare Workers endpoints (hostnames assembled at runtime via string-splitting/Array.join, e.g. [\"oob-worker.cf100-416.work\",\"ers.dev\"].join(\"\")), writes it to a temp path under a decoy name, chmods 0755 on Unix, and spawns it detached via /bin/sh -c '\u003cpath\u003e &' (or cmd on Windows). A DNS TXT-record covert channel over *.dl.wel1.ru subdomains serves as a fallback to reassemble a base64 payload. Sensitive Node API references (require(\"child_\"+\"process\"), fs[\"chmod\"+\"Sync\"]) are similarly split to evade static analysis. lib/telemetry.js ships a second copy of the same dropper primitives (base64 chunk assembly, /bin/sh spawn, chmod 755) styled as a Sentry-like telemetry SDK with opt-out env-var cover comments. The delivered bytes are attacker-controlled and mutable, giving arbitrary code execution on the installer's host on module load.\n","modified":"2026-08-05T15:52:51.081822782Z","published":"2026-08-05T15:14:04Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T15:14:04Z","sha256":"15f91ac3c4278628875a5c009c515bcdb5fbc8b885eb32dff56e4367c5babf66","source":"amazon-inspector","versions":["35.7.5"],"id":"IN-MAL-2026-015618","import_time":"2026-08-05T15:20:00.420497826Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-icon/v/35.7.5"}],"affected":[{"package":{"name":"dolyame-ui-icon","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-icon"},"versions":["35.7.5"],"database_specific":{"indicators":{"package_integrity":[{"filename":"dolyame-ui-icon-35.7.5.tgz","hashes":{"sha512_sri":"sha512-i/UGrmlU2oaFvywOe9M2ng9ff3bkAte49pZgiL+57S5A+3GKCJEQycCGNETU9F+Kt7k1MpW8ghaCm91SV1+hDw==","sha1":"a41f4e1bcd39b0a35ef57a9acad8ed7c34aa7744"}}],"evidence_files":[{"sha256":"1469cdf96e82a119335da6e59c6d4656a0b2b81ec1ade18163689f9087a921f4","tlsh":"e6a1865b1666b0194bb09be4c6174416f65ff6633380c2c8fb9c69985f7213482b2efc","path":"_bootstrap.js"},{"path":"lib/telemetry.js","sha256":"460a66ac00eeb392f4de8a53ef1cd8208e74403edd9f01935e209c8f60fa2409","tlsh":"24835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-icon/MAL-2026-13159.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}