{"schema_version":"1.8.0","id":"MAL-2026-13165","published":"2026-08-05T15:12:12Z","modified":"2026-08-05T15:52:53.782197388Z","summary":"Malicious code in dolyame-ui-list (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (db9f072ffe296e46cc8e680613ad548ddea1174c0cc481272a564c85860bfdb4)\nOn require() of dolyame-ui-list, index.js loads _vendor.js which downloads a platform-specific executable from one of four hardcoded Cloudflare Workers hosts (oob-worker.cf100-*.workers.dev through cf103-*.workers.dev) with a DNS TXT fallback discovery channel under *.dl.wel1.ru. Destination hostnames and API names are obfuscated via array-fragment join(\"\") and dynamic member access (e.g. require(\"child_\" + \"process\"), fs[\"chmod\" + \"Sync\"]). The fetched bytes are written to /var/tmp/.cache_<hex> on Linux/macOS or %TEMP%\\dotnet_diag_<hex>.exe on Windows (a lookalike name imitating a Microsoft diagnostic tool), chmodded 0755, and spawned detached via /bin/sh -c or cmd.exe /c start /b. No version pin, no hash or signature verification, and the hosts are not the publisher's infrastructure. Environment variables DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK are checked as a cover story consistent with a telemetry SDK. A second full copy of the same dropper ships as lib/telemetry.js (81 KB) with identical primitives, providing an alternate loader path. The package name resembles the Russian BNPL vendor Dolyame's UI ecosystem but the behavior matches no legitimate use.\n","affected":[{"package":{"name":"dolyame-ui-list","ecosystem":"npm","purl":"pkg:npm/dolyame-ui-list"},"versions":["35.2.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_vendor.js","sha256":"936bc6542c66f273425faed395bae778db94f5abe32591e3ccc0e2102823b258","tlsh":"6ea1a69616aa70188bb097e5c6074416f65bf6633380c2d4fb5ca9981f7712483b2efc"},{"path":"lib/telemetry.js","sha256":"fea46bb313a806ce0e9e6d119c4d45ebeda3f01e1a3e259daad8f1dd486caba2","tlsh":"87835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"dolyame-ui-list-35.2.6.tgz","hashes":{"sha1":"5e0ac0df8bc08e3bd821a0ccb3e245f8ae20ff26","sha512_sri":"sha512-sYK6et0+6R+8O1rctM6WimH2/cmBS9Or70HB7JU6YpEKKWp4uFN3lnjx6HLCe41/Yez9QEqMHslypQ3r4S7LAA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-list/MAL-2026-13165.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-list/v/35.2.6"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015606","import_time":"2026-08-05T15:20:00.021631854Z","modified_time":"2026-08-05T15:12:12Z","sha256":"db9f072ffe296e46cc8e680613ad548ddea1174c0cc481272a564c85860bfdb4","source":"amazon-inspector","versions":["35.2.6"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}