{"id":"MAL-2026-13189","summary":"Malicious code in dolyame-ui-table (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ed24a0ae9dfa9dd545fde1200d967a5625a2daf28ada90efb2ad78fe5bfdc73e)\nOn require of the package's main entry, `_compat.js` reconstructs Cloudflare Workers hostnames (oob-worker.cf99-9b3.workers.dev, cf100-416.workers.dev, cf101-adf.workers.dev, cf103-070.workers.dev) and a DNS-TXT fallback discovery host (sdk.dl.wel1.ru) from split string arrays joined at runtime, downloads a platform-specific binary via https.get, writes it under /tmp or %TEMP% with disguised names (dotnet_diag_\u003crand\u003e.exe,.cache_\u003crand\u003e), chmods 0o755, and spawns it detached via `/bin/sh -c` or `cmd`. Staging paths and destinations are runtime-assembled to evade literal string matching, and the payload uses cover-story naming resembling system diagnostics. The package presents itself as a UI table toolkit, which has no need for native binary downloads or subprocess execution.\n","modified":"2026-08-05T15:53:05.035466251Z","published":"2026-08-05T15:09:59Z","database_specific":{"malicious-packages-origins":[{"versions":["35.5.4"],"id":"IN-MAL-2026-015592","import_time":"2026-08-05T15:19:59.502129449Z","modified_time":"2026-08-05T15:09:59Z","sha256":"ed24a0ae9dfa9dd545fde1200d967a5625a2daf28ada90efb2ad78fe5bfdc73e","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-table/v/35.5.4"}],"affected":[{"package":{"name":"dolyame-ui-table","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-table"},"versions":["35.5.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_compat.js","sha256":"9cd45a630fa67a736fd7c02d326fd27a97b09216b532e5553ba48500aa4178ea","tlsh":"65a1b95a12aa701d4bb097e4c61b4426f69bf6533380d6c1fb9ca9984f761248372efc"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-2Rdw/wDsqSxPT1K/+UK9AnkwRQ7zbzl05nqyyHzCY4uZf+fy06Q9EO7MDMbxB0YlT32iKJByNu0RiSQw9Zs+8Q==","sha1":"e132ee9e6d4e9466f21d5416e975b35dd1c84de0"},"filename":"dolyame-ui-table-35.5.4.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-table/MAL-2026-13189.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}