{"id":"MAL-2026-13172","summary":"Malicious code in dolyame-ui-pagination (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7acc8dae4428c1b1cbf6ba1dc8199cdd4b07bf06aceca87a603fd34fd18834f7)\nOn require of the package, index.js loads./_polyfill.js, which immediately executes a dropper routine. The dropper assembles destination hostnames at runtime via array-join string splitting to evade static matching, resolving to Cloudflare Workers endpoints (oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev). A platform-specific binary is downloaded, written to /tmp or %TEMP% under disguised names such as.cache_\u003chex\u003e or dotnet_diag_\u003chex\u003e.exe, chmod'd to 0755, and spawned detached via /bin/sh -c or cmd. A secondary covert channel resolves TXT records under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, base64-decoding the concatenated TXT fragments into an executable buffer when the HTTPS mirrors fail. A sibling module lib/telemetry.js ships the same dropper primitives (base64-decoded buffer, split-property fs['chmod'+'Sync'], /bin/sh spawn) though it is not on the entrypoint graph from index.js. Destinations are unrelated to the package's stated purpose (a UI pagination component), unpinned, and unverified; the fetched bytes are opaque and executed.\n","modified":"2026-08-05T15:52:57.513963524Z","published":"2026-08-05T15:10:41Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T15:19:59.674747115Z","modified_time":"2026-08-05T15:10:41Z","sha256":"7acc8dae4428c1b1cbf6ba1dc8199cdd4b07bf06aceca87a603fd34fd18834f7","source":"amazon-inspector","versions":["35.2.5"],"id":"IN-MAL-2026-015596"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-pagination/v/35.2.5"}],"affected":[{"package":{"name":"dolyame-ui-pagination","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-pagination"},"versions":["35.2.5"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_polyfill.js","sha256":"92eb3fc8d556fd2974a879e57abe6d35c02519baf47eb8086fa7b4ad2c94c696","tlsh":"99b196a615a630188bb0d7e4c7176406f55bf6637780d2d8fb9ca5980fb621482b3efc"},{"path":"lib/telemetry.js","sha256":"c15769a4fd359fa44d08ea137f1c6612563f2030598e050a478b0436e9a6dcd7","tlsh":"07835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-i1oPitqbhTDWJ3VAh/B9kK34UcXF59xK7ZQmykKK1rfKc/KGq1YvJ1UYRWIjcJlPtOljGeHMvC3rp4abPPswIA==","sha1":"54011f314548333d3f7f2cb2c1710f0ba124efa7"},"filename":"dolyame-ui-pagination-35.2.5.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-pagination/MAL-2026-13172.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}