-= Per source details. Do not edit below this line.=-
On require of the package's main entry, index.js loads platform.js which assembles obfuscated hostnames via array.join("") to reach oob-worker.cf*.workers.dev, downloads a platform-specific binary, writes it to /var/tmp/.cache<hex> on POSIX or %TEMP%\dotnetdiag<hex>.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. A covert DNS-TXT fallback channel (loadViaDns) reads a chunk count from c.<domain> and base64-reassembles the executable payload from numbered TXT records under *.dl.wel1.ru. Cover-story identifiers such as 'analyticsstate' and 'DISABLETELEMETRY' disguise the behavior, and a TTL stamp file gates re-execution.
{
"malicious-packages-origins": [
{
"versions": [
"35.1.4"
],
"id": "IN-MAL-2026-015591",
"import_time": "2026-08-05T15:19:59.472272679Z",
"modified_time": "2026-08-05T15:09:50Z",
"source": "amazon-inspector",
"sha256": "c154e71b3fe4bf6957b180aa41ecdc789c11ea90928aab8c66c52a90c6428051"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-ukMfsBZh9/v4sY4sDdJP+nueNZFUS01k+4Qu0rYpLuKLYQBdPTHo1n4McFoNNjC4He8pKpn1uSsGYk732OmwRg==",
"sha1": "363e8332b736f075986897d36b8b4d011c8ca240"
},
"filename": "dolyame-ui-styles-35.1.4.tgz"
}
],
"evidence_files": [
{
"path": "_platform.js",
"tlsh": "eba1979616aa70188bb0a7e4c7174416f65bf6633781c284fb5ca9981fb21248272efc",
"sha256": "944ba2d4cb916fed278e8f3264e5df151e087b979e0b67ff020ffc6957c1d947"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-styles/MAL-2026-13187.json"