{"id":"MAL-2026-13185","summary":"Malicious code in dolyame-ui-stepper (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (25a9668418d3b01588efbd1a9385ae05b720cf72761700fe815d10d3d0e834b3)\nOn `require('dolyame-ui-stepper')`, index.js unconditionally loads _shim.js, which assembles hostnames from split string fragments (resolving to oob-worker.cf{101-adf,99-9b3,100-416,103-070}.workers.dev, with a DNS-TXT base64 fallback via {sdk,ext,pkg,net}.dl.wel1.ru), fetches a platform-matched native binary over https.get, writes it to a temporary path under a disguised name (dotnet_diag_\u003chex\u003e.exe on Windows,.cache_\u003chex\u003e on POSIX), chmods 0o755, and spawns it detached via `/bin/sh -c '\u003cfile\u003e &'` or `cmd.exe /c start /b`. A duplicate dropper implementation using the same primitives (base64 chunk assembly, chmod 755, detached spawn) is also staged in lib/telemetry.js under an 'Analytics SDK' cover story, though not reachable from the current main. The destination hosts are obfuscated via string-splitting, the dropped filename impersonates a Microsoft diagnostic tool, and the fetch-and-execute path fires on every import with no user interaction.\n","modified":"2026-08-05T15:53:03.788657202Z","published":"2026-08-05T15:09:25Z","database_specific":{"malicious-packages-origins":[{"versions":["35.7.5"],"id":"IN-MAL-2026-015588","import_time":"2026-08-05T15:19:59.368989464Z","modified_time":"2026-08-05T15:09:25Z","sha256":"25a9668418d3b01588efbd1a9385ae05b720cf72761700fe815d10d3d0e834b3","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-stepper/v/35.7.5"}],"affected":[{"package":{"name":"dolyame-ui-stepper","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-stepper"},"versions":["35.7.5"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"5fb837ab52e0e0f38b6de15c6d2ad349a2a7075b184f8c4b35c50bd66022732a","tlsh":"e6a1869a126530084bb0abe58b174416f65bfa633780c595fb9cb5d51f72124c3b2efc","path":"_shim.js"},{"path":"lib/telemetry.js","sha256":"82154395c838d8a66aea5687352e93085bbc59375b5299207076a05a41ffb017","tlsh":"c7835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"dolyame-ui-stepper-35.7.5.tgz","hashes":{"sha1":"5c830b5389c9b1fa69e4df09b7b3786ef39e605a","sha512_sri":"sha512-yceB4BZ+x7lPjadJLqE1LNM6zstq2zZFKoRkV5M64W6yAcjOpynhNpgowOD4RqqwUcjgqkpBYttmIM2MaeygAw=="}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-stepper/MAL-2026-13185.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}