-= Per source details. Do not edit below this line.=-
On require of the package's main entry, index.js loads platform.js which assembles obfuscated hostnames via array.join("") to reach oob-worker.cf*.workers.dev, downloads a platform-specific binary, writes it to /var/tmp/.cache on POSIX or %TEMP%\dotnet_diag_.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. A covert DNS-TXT fallback channel (loadViaDns) reads a chunk count from c. and base64-reassembles the executable payload from numbered TXT records under *.dl.wel1.ru. Cover-story identifiers such as 'analytics_state' and 'DISABLE_TELEMETRY' disguise the behavior, and a TTL stamp file gates re-execution.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-015591",
"import_time": "2026-08-05T15:19:59.472272679Z",
"modified_time": "2026-08-05T15:09:50Z",
"sha256": "c154e71b3fe4bf6957b180aa41ecdc789c11ea90928aab8c66c52a90c6428051",
"source": "amazon-inspector",
"versions": [
"35.1.4"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "_platform.js",
"sha256": "944ba2d4cb916fed278e8f3264e5df151e087b979e0b67ff020ffc6957c1d947",
"tlsh": "eba1979616aa70188bb0a7e4c7174416f65bf6633781c284fb5ca9981fb21248272efc"
}
],
"package_integrity": [
{
"filename": "dolyame-ui-styles-35.1.4.tgz",
"hashes": {
"sha1": "363e8332b736f075986897d36b8b4d011c8ca240",
"sha512_sri": "sha512-ukMfsBZh9/v4sY4sDdJP+nueNZFUS01k+4Qu0rYpLuKLYQBdPTHo1n4McFoNNjC4He8pKpn1uSsGYk732OmwRg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-styles/MAL-2026-13187.json"