-= Per source details. Do not edit below this line.=-
On require() of the package, index.js loads vendor.js which downloads a platform-specific binary from hardcoded Cloudflare workers.dev hosts (oob-worker.cf10{1,2,3}-*.workers.dev) with a DNS-TXT chunked base64 fallback resolved via sdk.dl.wel1.ru, writes it to /tmp or the Windows Temp directory under a disguised name (.cache<hex> or dotnetdiag<hex>.exe), chmods 755, and spawns it detached via /bin/sh -c "<path> &" or cmd.exe /c start /b. Destination hostnames and dangerous APIs are assembled by array-join and string concatenation (e.g. require("child_"+"process"), fs["chmod"+"Sync"]) to hinder pattern-matching. A second, structurally identical dropper is shipped in lib/telemetry.js under an 'Analytics SDK' label, providing a backup payload vector. The advertised purpose (a UI flag component) has no relationship to fetching and executing opaque native binaries from anonymous Workers hosts.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-015621",
"import_time": "2026-08-05T15:20:00.511209859Z",
"sha256": "be48c86f2b67912c3cfa1849431e5eb3d45510c55bb1fa98ab304dc36d25097b",
"modified_time": "2026-08-05T15:14:34Z",
"versions": [
"35.7.6"
],
"source": "amazon-inspector"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-YLymA1VppXy8nP+AhfmJUch8NBMVBEEDpeheaC/rleqsgCwAaj2PAkJetWTEZ9jIq3xp1rWF+pfP1kJ80Dc+ew==",
"sha1": "c975cde6205536d52f3820642b9b5d6758f1782b"
},
"filename": "dolyame-ui-flag-35.7.6.tgz"
}
],
"evidence_files": [
{
"path": "_vendor.js",
"sha256": "dd017d0359480ff311cd0a41b6710e59e914cd8eb493a2906cda3fcf4f5ad95b",
"tlsh": "7da1a99a12a5b0188fb0d7e0c71b9815f65bf663368182d4f79c65944f731248372dfc"
},
{
"path": "lib/telemetry.js",
"sha256": "c5be733436d7d5b4876806970b3686136a813084243ab1e8a4ab22fb7074ad09",
"tlsh": "1e835056566a142186b2b368df234107ff3685272642429dbafc82dc1fbd72092a5ffc"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-flag/MAL-2026-13155.json"