-= Per source details. Do not edit below this line.=-
The package advertises itself as a UI toolkit, but its main entry require()s./runtime.js, which on load downloads a platform-specific binary from author-controlled Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev), writes it to /var/tmp/.cache<rand> or %TEMP%/dotnetdiag<rand>.exe, chmods 0755, and spawns it detached via cp.spawn("/bin/sh", ["-c", fp+" &"], {detached:true}).unref(). Host and domain strings are assembled at runtime from split-string arrays (e.g. ['sdk.dl.w','el1.r','u'].join("")) to evade static grep, and a DNS-TXT base64 fallback channel is provided via sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. Execution is gated on the absence of DISABLETELEMETRY/ANALYTICSOPTOUT/DONOTTRACK and rate-limited via a /tmp/.analyticsstate mtime stamp; comments frame the behavior as 'telemetry' cleanup. Filenames (.cache_*, dotnetdiag*.exe) are chosen to blend into system tmp contents. The download-and-execute path has no relationship to the stated UI-toolkit purpose.
{
"malicious-packages-origins": [
{
"versions": [
"35.4.6"
],
"id": "IN-MAL-2026-015624",
"import_time": "2026-08-05T15:20:00.694171981Z",
"modified_time": "2026-08-05T15:14:57Z",
"source": "amazon-inspector",
"sha256": "81324df09668ea22833f1cff69d3e861bbb0644e5f231028ef2ea8ba0f9b8631"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"filename": "dolyame-ui-draggable-35.4.6.tgz",
"hashes": {
"sha512_sri": "sha512-PJZBnjc4R37Ee6kFlf1dnT8qIeT1N2MWgOw5EvNU6Y0HZlS8k/r/zhOtUQjbm8wrke9DWu9LRURO0af/VAWfSA==",
"sha1": "5840251ca9dfda7163c38ecab00aac02940d9a8c"
}
}
],
"evidence_files": [
{
"path": "_runtime.js",
"tlsh": "8da1975606a770284bb097f486174416f65bf6633380c284fb9c69881fb711483b2efc",
"sha256": "4359d37961b2c16fd609af42d9bf6a8892fcc2a97cdea2e99cf5ee4a09307271"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-draggable/MAL-2026-13151.json"