{"schema_version":"1.8.0","id":"MAL-2026-13144","published":"2026-08-05T15:16:05Z","modified":"2026-08-05T15:52:43.999767855Z","summary":"Malicious code in dolyame-ui-checkbox (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2a445ffd0f222f7d58ad870ad641f9dd2fb21a1cc43795cbef5c58109cafebbe)\nOn require of the package, index.js loads _vendor.js, which reconstructs a set of C2 hostnames from string-split fragments (four *.workers.dev mirrors and a *.dl.wel1.ru DNS-TXT fallback), selects a per-platform endpoint, downloads an attacker-controlled binary via https.get (or reassembles it from chunked base64 DNS TXT records at c.<domain>/<i>.<domain> when HTTPS is blocked), writes it to /var/tmp on Unix or %TEMP% on Windows under cover-story names such as.cache_<hex> or dotnet_diag_<hex>.exe, chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. A second, functionally equivalent dropper is packaged as lib/telemetry.js (81 KB), disguised as an analytics SDK, implementing the same fetch->chmod 755->spawn('/bin/sh','-c', path+' &') pattern with a base64-decoded payload path. Host reconstruction via string-splitting and the DNS-TXT covert transport are anti-analysis features paired with the dropper.\n","affected":[{"package":{"name":"dolyame-ui-checkbox","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-checkbox"},"versions":["35.6.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_vendor.js","sha256":"dec2d9ed93f1d1221ca47a48f208bed542fe1d0bc1f2f545ebb7ad8f238bbd70","tlsh":"0ea1859a12a970184bb097e0c61b4415f95bf6633780d295fb5ca9985fb602483b2efc"},{"path":"lib/telemetry.js","sha256":"e69c6a5ef987e7b69c3f46d197fd568e24039d3d30c400669a9815250db17f77","tlsh":"14835055566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"dolyame-ui-checkbox-35.6.9.tgz","hashes":{"sha1":"d4917cea98efc56fa8dc7a60385ee3da3fbe452d","sha512_sri":"sha512-BXxRHyDyjbEhaJjk+uYDg5+XzmM1YR9R+ix0US5gjypHvbhc7BoRsBkd92FPg3mwflUNIJgXb/CEDzMexuMUzA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-checkbox/MAL-2026-13144.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-checkbox/v/35.6.9"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015631","import_time":"2026-08-05T15:20:00.987517906Z","modified_time":"2026-08-05T15:16:05Z","sha256":"2a445ffd0f222f7d58ad870ad641f9dd2fb21a1cc43795cbef5c58109cafebbe","source":"amazon-inspector","versions":["35.6.9"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}