{"id":"MAL-2026-13196","summary":"Malicious code in dolyame-ui-toggle (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e9a2d0e912bed4c7005a9945215406319204611c186b19d77065d1a5216e5fb1)\nRequiring the package loads _ext.js, which downloads a platform-specific binary from obfuscated *.workers.dev endpoints (with a DNS-TXT base64 fallback via *.dl.wel1.ru), writes it to /var/tmp or %TEMP% under disguised names such as '.cache_\u003ctag\u003e' or 'dotnet_diag_\u003ctag\u003e.exe', chmods it 0755, and spawns it detached via '/bin/sh -c' or 'cmd.exe /c start /b'. Endpoint hostnames and resolver domains are constructed by joining fragment arrays to evade string scans, and the dropped file names impersonate telemetry/diagnostic artifacts. The package's declared purpose is a trivial UI toggle; the fetched, unpinned, unverified binary is unrelated to that purpose. The result is arbitrary attacker-controlled code execution on any machine that installs or imports this version.\n","modified":"2026-08-05T15:53:08.452718379Z","published":"2026-08-05T15:08:02Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.4.1"],"id":"IN-MAL-2026-015579","import_time":"2026-08-05T15:19:58.913308859Z","modified_time":"2026-08-05T15:08:02Z","sha256":"e9a2d0e912bed4c7005a9945215406319204611c186b19d77065d1a5216e5fb1"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-toggle/v/35.4.1"}],"affected":[{"package":{"name":"dolyame-ui-toggle","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-toggle"},"versions":["35.4.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"a1b1975a027670194fb0d7e4c61b8826f55bf66337808284fb5ca5945f7312883b2efc","path":"_ext.js","sha256":"3c10c6b81a3fd5405141194e9f5906e878a03dccf2fc6c7de2f98680beb658a4"}],"package_integrity":[{"filename":"dolyame-ui-toggle-35.4.1.tgz","hashes":{"sha1":"3e23e7e5177cbdac884bc7546ab953213a8e81d4","sha512_sri":"sha512-I9Hpi6PAHFbhRMWHVbELdaSgKZ/26Sol0YSWyGKP2/k31JuWJAxEL/w7qmgoF8sMNiHIo7XhgnZaOu60UqF++w=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-toggle/MAL-2026-13196.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}