{"id":"MAL-2026-13197","summary":"Malicious code in dolyame-ui-tooltip (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0fa2102880c7088cf1644fc7731a7fc59b6406477c1939e2dbc0382e8724ad20)\nThe package advertises itself as a tooltip UI component but its main entry (index.js) unconditionally requires./_adapter, which at load time selects a platform-specific endpoint, downloads an opaque binary from obfuscated Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev) with a DNS-TXT fallback to sdk.dl.wel1.ru, writes it to a temp path under decoy names such as dotnet_diag_\u003chex\u003e.exe or.cache_\u003chex\u003e, chmods it 0755 on POSIX, and detach-spawns it via cmd.exe or /bin/sh -c. Network destinations and the child_process module name are reconstructed from split-string arrays (e.g. ['sdk.dl.we','l1','.r','u'].join(''), require('child_' + 'process')) to hide them from static inspection. A UI tooltip library has no legitimate need for network I/O, child_process, or execution of unsigned remote binaries; the telemetry/analytics self-labeling is a cover story for full-host remote code execution against the installer.\n","modified":"2026-08-05T15:53:09.201877388Z","published":"2026-08-05T15:07:35Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015576","import_time":"2026-08-05T15:19:58.825279953Z","modified_time":"2026-08-05T15:07:35Z","sha256":"0fa2102880c7088cf1644fc7731a7fc59b6406477c1939e2dbc0382e8724ad20","source":"amazon-inspector","versions":["35.8.8"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-tooltip/v/35.8.8"}],"affected":[{"package":{"name":"dolyame-ui-tooltip","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-tooltip"},"versions":["35.8.8"],"database_specific":{"indicators":{"evidence_files":[{"path":"_adapter.js","sha256":"37be52102a1091a9789dac16dfeb24f41ca25f165a8588d2ee82be31141a49fc","tlsh":"eda1755a06a670188bb0ebe0c717482af65ef6633781c294fb9c65945f735248372efc"}],"package_integrity":[{"filename":"dolyame-ui-tooltip-35.8.8.tgz","hashes":{"sha1":"9157da91fa81a1683f42332f0e76dc1d14c27169","sha512_sri":"sha512-wNyTrIqZsACujCuDpng4pCo5Jx0e6oce0FbiHSYmThWrhRQnr9mZNL8RgLqOoZE8eHi/oiboge66fmJmlZZclA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-tooltip/MAL-2026-13197.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}