-= Per source details. Do not edit below this line.=-
On require of the package, index.js loads bridge.js, which reconstructs C2 hostnames from split string fragments (resolving to oob-worker.cf103-07.workers.dev, oob-worker.cf99-9b3.workers.dev, and oob-worker.cf100-416.workers.dev), downloads a platform-specific binary from /pkg/package[.exe|-arm64|mac], writes it to /var/tmp/.cache<hex> or %TEMP%\dotnetdiag_<hex>.exe, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. A DNS TXT covert channel over *.dl.wel1.ru (c.<domain> count + <n>.<domain> base64 chunks) provides a fallback transport when HTTPS egress is blocked. Cover-story identifiers such as analytics and dotnet_diag disguise the payload, and a ~20455s persistence flag paces re-execution. A second, larger dropper variant with the same behavior ships as lib/telemetry.js (~81KB) under an analytics-sdk cover story, ready to be wired in.
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T15:10:18Z",
"sha256": "1d1d8b1348e86f0f476ab27b5d5cde1c6a4cfd519e74e526a82263c78a0aaf6b",
"import_time": "2026-08-05T15:19:59.611796285Z",
"id": "IN-MAL-2026-015594",
"versions": [
"35.9.5"
]
}
]
}{
"package_integrity": [
{
"filename": "dolyame-ui-select-35.9.5.tgz",
"hashes": {
"sha512_sri": "sha512-SvV5oxDIBAVMsi9jRdFzKqaxwpPoFJITzPByUU1KhCwuhFwD3HRDLHSVykz/D4xrcJBThA6yilagKLVUn846ew==",
"sha1": "1837deb1fbfb013403cc5c60425fbefeca1e435a"
}
}
],
"evidence_files": [
{
"tlsh": "0fa1776a16a570098b70d7e0c6175416f65bf66333c092d8fb9c69884fb222483f2efc",
"sha256": "593f8ed8edc1bbacf4ee3e187fd130856412a78834ec0fc618fa928729b00bab",
"path": "_bridge.js"
},
{
"tlsh": "aa835056566a142186b2b368df234107ff3685272642429dbafc82dc1fbd72092a5ffc",
"sha256": "d8c4b61a5d4bedf2b3b95f8c03b8ffa4e2708e3262e024e8488991ae29810b32",
"path": "lib/telemetry.js"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-select/MAL-2026-13182.json"
[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]