{"id":"MAL-2026-13179","summary":"Malicious code in dolyame-ui-react-version-switch (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1ee4e207fd01bae956d7fe084377ecea438f81774ea01ca6b02a50c1962c6cca)\nPackage advertises itself as a React UI helper but its index.js unconditionally require()s./_vendor at load time. _vendor.js selects a platform-specific asset path, fetches bytes over HTTPS from a randomly-ordered pool of string-split-obfuscated hosts assembled via.join('') (oob-worker.cf*.workers.dev and sdk/ext/pkg/net.dl.wel1.ru), with a DNS-TXT chunked-base64 fallback to bypass HTTPS filtering. The downloaded bytes are written to /tmp or %TEMP% under disguised names such as dotnet_diag_\u003chex\u003e.exe or.cache_\u003chex\u003e, chmod 0755'd on POSIX, and spawned detached via /bin/sh or cmd.exe. No hash verification is performed despite a cover-story comment claiming a SHA-256 integrity check. The package's declared 'interface elements' purpose is a cover story: index.js is a trivial no-op class stub, and the dropper is the only functional behavior.\n","modified":"2026-08-05T15:53:00.413670807Z","published":"2026-08-05T15:11:54Z","database_specific":{"malicious-packages-origins":[{"sha256":"1ee4e207fd01bae956d7fe084377ecea438f81774ea01ca6b02a50c1962c6cca","source":"amazon-inspector","versions":["35.6.1"],"id":"IN-MAL-2026-015604","import_time":"2026-08-05T15:19:59.942523668Z","modified_time":"2026-08-05T15:11:54Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-react-version-switch/v/35.6.1"}],"affected":[{"package":{"name":"dolyame-ui-react-version-switch","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-react-version-switch"},"versions":["35.6.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"8055a93e18a4d8a7e49dab9b5df62526cc69c80fc79e00c0f3c6a2e7af29a9fc","tlsh":"7ab1a85a16aa71094bb0abe4c7174415f65ff6633381c198fb9c69981f7212483f2efc","path":"_vendor.js"},{"tlsh":"e6f04c9520dba42386b177e2ca720052f66387350a4f01a87ed940fe0ff0c584298fbe","path":"index.js","sha256":"2ce23f4adf54a4693a4be8e02ac1edd1e2278e2298e05726f0b2d2e57e0d3fb8"}],"package_integrity":[{"filename":"dolyame-ui-react-version-switch-35.6.1.tgz","hashes":{"sha512_sri":"sha512-Qss/q/dhQbnVUyM38X3cr2+rgWhwBtQ08P292lFAPoPLh1S6AC5jPzxNxe52+mafopL5ruAkdjasSE+20mmhKQ==","sha1":"b4375a75689a4b7af88b661ebf565840d28ff056"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-react-version-switch/MAL-2026-13179.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}