{"id":"MAL-2026-13587","summary":"Malicious code in dolyame-ui-inputtools (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b19507e10e8c209d60c32cbff9d46f8cc96774c67892192be7550d75064cfb63)\nOn require(), index.js loads _bridge.js which assembles per-platform executable URLs from string-split fragments resolving to rotating Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, cf102-baf, cf99-9b3, cf101-adf) and *.dl.wel1.ru (sdk/ext/pkg/net subdomains), with a DNS TXT covert-channel fallback that reassembles base64 chunks from numbered subdomain TXT records. Downloaded bytes are written to /tmp or %TEMP% under disguised names (.cache_\u003chex\u003e, dotnet_diag_\u003chex\u003e.exe), chmod 0755, and spawned detached via cp.spawn(\"/bin/sh\", [\"-c\", fp + \" &\"], {detached:true}).unref(). No hash or signature verification is performed and the destinations are not publisher infrastructure. The same fetch-\u003ewrite-\u003echmod+x-\u003edetached-spawn chain is duplicated in lib/telemetry.js (the package's main export), which frames itself as an 'Analytics SDK / observability' module and obfuscates the child_process require via string concatenation (require(\"child_\"+\"process\")) and the fs.chmodSync call via fs[\"chmod\"+\"Sync\"]. The 'ui-inputtools' package name and the telemetry cover story do not match the shipped behavior.\n","modified":"2026-08-07T13:20:47.565819473Z","published":"2026-08-07T12:23:40Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-07T12:23:40Z","sha256":"b19507e10e8c209d60c32cbff9d46f8cc96774c67892192be7550d75064cfb63","source":"amazon-inspector","versions":["35.8.1"],"id":"IN-MAL-2026-016962","import_time":"2026-08-07T12:51:19.932063697Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-inputtools/v/35.8.1"}],"affected":[{"package":{"name":"dolyame-ui-inputtools","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-inputtools"},"versions":["35.8.1"],"database_specific":{"indicators":{"evidence_files":[{"path":"_bridge.js","sha256":"6aa5c0836332719f6d66ca5553c78e17d82c91fbf68515f89ec504419ae149e9","tlsh":"29a1965a16fa30180692f1d8851f541a719efa833284e9d4fb4c66955f96238c3b29ec"},{"sha256":"d1fc24218d888a158ca7d1fd4455c6fc0587b34c0d2174e680fd2e4698bd228a","tlsh":"9c73304966fb10214263b0685fab40437635c4072a4eed5dba9c43ec9f8db3896f1fb9","path":"lib/telemetry.js"}],"package_integrity":[{"filename":"dolyame-ui-inputtools-35.8.1.tgz","hashes":{"sha512_sri":"sha512-k8AvLOKiY/5N6j6PBX0ckoPJX0DFvhC91Om98SEuX4j4RJ+HJ0g4Ys092QVYHfDIiUAsdMoKFBZC1AgTEM1edQ==","sha1":"020ca5b252a38eeaf471f9a4a0adc278243d8477"}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-inputtools/MAL-2026-13587.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}