{"id":"MAL-2026-13186","summary":"Malicious code in dolyame-ui-storybook-menu (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f0df8669e15c61895263cb0fc334c38027fe01b749646c3d3f74baee35684cb1)\nThe package's main entry `index.js` unconditionally requires `_ext.js`, which on module load selects a platform-specific asset, fetches an opaque binary from one of three Cloudflare Workers hostnames whose literals are reconstructed at runtime via array `.join(\"\")` splitting (oob-worker.cf100-416.workers.dev and two siblings) with a DNS TXT fallback under `*.dl.wel1.ru`, writes the bytes to a temp path disguised as a system file (`.cache_\u003chex\u003e` on POSIX, `dotnet_diag_\u003chex\u003e.exe` on Windows), `chmod 0755` on POSIX, and spawns it detached via `/bin/sh -c... &` or `cmd.exe /c start /b`. A stamp file named `.analytics_state` and gating on `DISABLE_TELEMETRY` / `ANALYTICS_OPT_OUT` / `DO_NOT_TRACK`, plus a sibling `lib/telemetry.js` reusing the same download-chmod-spawn primitives under an 'Analytics SDK' framing, present the behavior as telemetry, but the destinations are hostname-obfuscated Cloudflare Worker endpoints unrelated to the package's stated purpose and the delivered content is an executed binary. This is a full remote-code-execution dropper that fires on any `require('dolyame-ui-storybook-menu')` and thus on default install/import in any consumer.\n","modified":"2026-08-05T15:53:03.782961430Z","published":"2026-08-05T15:09:33Z","database_specific":{"malicious-packages-origins":[{"sha256":"f0df8669e15c61895263cb0fc334c38027fe01b749646c3d3f74baee35684cb1","source":"amazon-inspector","versions":["35.5.6"],"id":"IN-MAL-2026-015589","import_time":"2026-08-05T15:19:59.405994734Z","modified_time":"2026-08-05T15:09:33Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-storybook-menu/v/35.5.6"}],"affected":[{"package":{"name":"dolyame-ui-storybook-menu","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-storybook-menu"},"versions":["35.5.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_ext.js","sha256":"dcf5a607ee2d96bd0363ea4c67cd416157904fe31fb07373ff91e0c8c5cdc8dc","tlsh":"39a1975b126a70184b70ebe4ca1b4416f65af6633381c5c4fb5cb9981fb212483b2efc"}],"package_integrity":[{"hashes":{"sha1":"bc599c5e67843a24e93b4074129566e49297079b","sha512_sri":"sha512-4tSzQ8WkOQqXPCvoKsrD0UJ9Wff65780Pk/KdbQayq0T9FSY+ZIyqJZYhChcNoiEgerIRgs+nSAQR8vmP2CQNA=="},"filename":"dolyame-ui-storybook-menu-35.5.6.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-storybook-menu/MAL-2026-13186.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}