{"id":"MAL-2026-13187","summary":"Malicious code in dolyame-ui-styles (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c154e71b3fe4bf6957b180aa41ecdc789c11ea90928aab8c66c52a90c6428051)\nOn require of the package's main entry, index.js loads _platform.js which assembles obfuscated hostnames via array.join(\"\") to reach oob-worker.cf*.workers.dev, downloads a platform-specific binary, writes it to /var/tmp/.cache_\u003chex\u003e on POSIX or %TEMP%\\dotnet_diag_\u003chex\u003e.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. A covert DNS-TXT fallback channel (loadViaDns) reads a chunk count from c.\u003cdomain\u003e and base64-reassembles the executable payload from numbered TXT records under *.dl.wel1.ru. Cover-story identifiers such as 'analytics_state' and 'DISABLE_TELEMETRY' disguise the behavior, and a TTL stamp file gates re-execution.\n","modified":"2026-08-05T15:53:04.063605479Z","published":"2026-08-05T15:09:50Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T15:09:50Z","sha256":"c154e71b3fe4bf6957b180aa41ecdc789c11ea90928aab8c66c52a90c6428051","source":"amazon-inspector","versions":["35.1.4"],"id":"IN-MAL-2026-015591","import_time":"2026-08-05T15:19:59.472272679Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-styles/v/35.1.4"}],"affected":[{"package":{"name":"dolyame-ui-styles","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-styles"},"versions":["35.1.4"],"database_specific":{"indicators":{"evidence_files":[{"path":"_platform.js","sha256":"944ba2d4cb916fed278e8f3264e5df151e087b979e0b67ff020ffc6957c1d947","tlsh":"eba1979616aa70188bb0a7e4c7174416f65bf6633781c284fb5ca9981fb21248272efc"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-ukMfsBZh9/v4sY4sDdJP+nueNZFUS01k+4Qu0rYpLuKLYQBdPTHo1n4McFoNNjC4He8pKpn1uSsGYk732OmwRg==","sha1":"363e8332b736f075986897d36b8b4d011c8ca240"},"filename":"dolyame-ui-styles-35.1.4.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-styles/MAL-2026-13187.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}