-= Per source details. Do not edit below this line.=-
On require('dolyame-ui-stepper'), index.js unconditionally loads shim.js, which assembles hostnames from split string fragments (resolving to oob-worker.cf{101-adf,99-9b3,100-416,103-070}.workers.dev, with a DNS-TXT base64 fallback via {sdk,ext,pkg,net}.dl.wel1.ru), fetches a platform-matched native binary over https.get, writes it to a temporary path under a disguised name (dotnetdiag<hex>.exe on Windows,.cache<hex> on POSIX), chmods 0o755, and spawns it detached via /bin/sh -c '<file> &' or cmd.exe /c start /b. A duplicate dropper implementation using the same primitives (base64 chunk assembly, chmod 755, detached spawn) is also staged in lib/telemetry.js under an 'Analytics SDK' cover story, though not reachable from the current main. The destination hosts are obfuscated via string-splitting, the dropped filename impersonates a Microsoft diagnostic tool, and the fetch-and-execute path fires on every import with no user interaction.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-015588",
"import_time": "2026-08-05T15:19:59.368989464Z",
"sha256": "25a9668418d3b01588efbd1a9385ae05b720cf72761700fe815d10d3d0e834b3",
"versions": [
"35.7.5"
],
"source": "amazon-inspector",
"modified_time": "2026-08-05T15:09:25Z"
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "_shim.js",
"tlsh": "e6a1869a126530084bb0abe58b174416f65bfa633780c595fb9cb5d51f72124c3b2efc",
"sha256": "5fb837ab52e0e0f38b6de15c6d2ad349a2a7075b184f8c4b35c50bd66022732a"
},
{
"path": "lib/telemetry.js",
"tlsh": "c7835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc",
"sha256": "82154395c838d8a66aea5687352e93085bbc59375b5299207076a05a41ffb017"
}
],
"package_integrity": [
{
"filename": "dolyame-ui-stepper-35.7.5.tgz",
"hashes": {
"sha1": "5c830b5389c9b1fa69e4df09b7b3786ef39e605a",
"sha512_sri": "sha512-yceB4BZ+x7lPjadJLqE1LNM6zstq2zZFKoRkV5M64W6yAcjOpynhNpgowOD4RqqwUcjgqkpBYttmIM2MaeygAw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-stepper/MAL-2026-13185.json"